ZeroHour

CVE-2023-36033

KEVmass1

Local Privilege Escalation in Microsoft Windows DWM Core Library

CISA: Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
12%p96
Published
()
KEV added
AI analysis

A flaw in the Windows Desktop Window Manager (DWM) Core Library — classified as an untrusted pointer dereference/memory-bounds issue (CWE-822, CWE-119) — allows a local, low-privileged attacker to elevate privileges on affected Windows systems. Per the CVSS vector, exploitation requires only the ability to execute code on the target (local vector, low privileges) and no user interaction. A successful attacker runs code with elevated privileges, gaining high-impact control of confidentiality, integrity, and availability on the host, typically as a post-compromise escalation step after initial access. All systems running Windows 10 1809/21H2/22H2, Windows 11 21H2/22H2/23H2, Windows Server 2019, or Windows Server 2022 (including the 23H2 edition) are affected. The vulnerability is confirmed to be exploited in the wild: CISA added it to the KEV on 2023-11-14, Microsoft's November 2023 Patch Tuesday fixed it among three actively exploited zero-days, public coverage notes active exploitation including reported QakBot malware campaigns, and it carries an elevated EPSS of roughly 12% within 30 days (96th percentile).

What to do: Apply the November 2023 (November 14, 2023) cumulative Windows updates to all Windows 10 1809/21H2/22H2, Windows 11 21H2/22H2/23H2, Windows Server 2019, and Windows Server 2022 (including 23H2) systems, prioritizing servers, RDS hosts, and shared-use machines. Because the flaw is used as a post-compromise escalation step in the wild (KEV-listed, with public reporting tied to QakBot campaigns), assume possible compromise on unpatched endpoints and hunt for follow-on malware, credential theft, and persistence activity; verify patch levels across the fleet rather than relying on mitigations, as CISA lists patching per vendor instructions as the required action.

Affected
Microsoft Windows 101809, 21H2, 22H2
Microsoft Windows 1121H2, 22H2, 23H2
Microsoft Windows Server 2019all supported releases
Microsoft Windows Server 2022Windows Server 2022 and Windows Server 2022, 23H2 edition
Estimated exposure
masshundreds of millions of Windows client and server endpoints (the Windows 10 1809+ through Windows 11 23H2 and Server 2019/2022 population; exact unpatched… — The DWM Core Library is a default component of every Windows installation and the listed versions span the mainstream Windows client and server installed base, which runs to hundreds of millions of devices, so the exposed population is far…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows DWM Core Library Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-822, CWE-119
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news