ZeroHour

CVE-2026-21519

KEVmass

Type Confusion Local Privilege Escalation in Microsoft Windows Desktop Window Manager

CISA: Microsoft Windows Type Confusion Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p84
Published
()
KEV added
AI analysis

CVE-2026-21519 is a type confusion flaw (CWE-843) in the Windows Desktop Window Manager, where accessing a resource using an incompatible type allows an authorized, low-privileged local user to elevate privileges. An attacker must already be able to run code on the target, for example via malware or a compromised account, and gains higher local privileges on the machine upon successful exploitation. The affected list spans all supported Windows 10 and Windows 11 client builds and Windows Server 2016 through 2025, so virtually every current Windows deployment is in scope. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-02-10 and it is among the six actively exploited zero-days fixed in Microsoft's February 2026 Patch Tuesday, though no public proof-of-concept is known and ransomware use is not confirmed.

What to do: Apply Microsoft's February 2026 security updates to all affected Windows 10, Windows 11, and Windows Server builds as a priority, since the flaw is being actively exploited and is on CISA's KEV catalog, making it subject to BOD 22-01 remediation timelines for federal agencies. Because this is a local privilege escalation requiring prior code execution, treat any already-compromised or unpatched endpoint as at risk of full privilege gain, and confirm remediation via Windows Update history or your patch-management tooling; ransomware linkage is unconfirmed but post-compromise LPEs of this kind are commonly chained in attacks.

Affected
Microsoft Windows 101607, 1809, 21H2, 22H2
Microsoft Windows 1123H2, 24H2, 25H2
Microsoft Windows Server2016, 2019, 2022, 2022 23H2, 2025
Estimated exposure
mass≈1 billion+ Windows devices (all supported Windows 10/11 client and Windows Server builds are listed) — The affected version list covers every currently supported Windows 10 and Windows 11 client build plus Windows Server 2016–2025, and Windows 10/11 run on the overwhelming majority of the world's roughly 1.4 billion Windows devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2, windows server 2025
Weakness
CWE-843
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news