ZeroHour

CVE-2026-69775

mass

Use-After-Free Privilege Escalation in Windows DWM Core Library

CVSS 3.1
7.1 high
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-69775 is a use-after-free vulnerability (CWE-416) in the Windows DWM Core Library, the Desktop Window Manager component responsible for rendering windows and the desktop. An attacker who already holds low-privileged authorized access could trigger the bug over a network, causing the DWM Core Library to access memory that has already been freed; the high attack-complexity and required user interaction make reliable exploitation more difficult. Successful exploitation allows the attacker to elevate privileges on the target system. Because the DWM Core Library is present in essentially all modern Windows installations, any Windows system is potentially in scope, with the highest risk on systems reachable through network/remote display sessions. There is currently no known public proof-of-concept, no confirmed in-the-wild exploitation, no CISA KEV listing, and EPSS estimates only a 0.5% probability of exploitation within 30 days.

What to do: Install the Windows security update from Microsoft's monthly Patch Tuesday release that fixes CVE-2026-69775, and check Microsoft's advisory for the exact affected builds since they are not listed in the available data. Until patched, harden network remote-session access such as RDP (restrict exposure, require VPN/MFA) because the attack vector is network-based with low-privilege access required. Watch for newly published PoCs or a CISA KEV addition, which would raise priority.

Affected
Microsoft Windows DWM Core Library (Desktop Window Manager)
Estimated exposure
mass~1 billion+ Windows installations (DWM is a core component of every modern Windows desktop) — The DWM Core Library ships in all modern Windows client and server releases, and Microsoft has publicly cited more than 1.4 billion monthly active Windows devices, so the potentially affected base is the entire Windows installed base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.