CVE-2026-69775
massUse-After-Free Privilege Escalation in Windows DWM Core Library
CVE-2026-69775 is a use-after-free vulnerability (CWE-416) in the Windows DWM Core Library, the Desktop Window Manager component responsible for rendering windows and the desktop. An attacker who already holds low-privileged authorized access could trigger the bug over a network, causing the DWM Core Library to access memory that has already been freed; the high attack-complexity and required user interaction make reliable exploitation more difficult. Successful exploitation allows the attacker to elevate privileges on the target system. Because the DWM Core Library is present in essentially all modern Windows installations, any Windows system is potentially in scope, with the highest risk on systems reachable through network/remote display sessions. There is currently no known public proof-of-concept, no confirmed in-the-wild exploitation, no CISA KEV listing, and EPSS estimates only a 0.5% probability of exploitation within 30 days.
What to do: Install the Windows security update from Microsoft's monthly Patch Tuesday release that fixes CVE-2026-69775, and check Microsoft's advisory for the exact affected builds since they are not listed in the available data. Until patched, harden network remote-session access such as RDP (restrict exposure, require VPN/MFA) because the attack vector is network-based with low-privilege access required. Watch for newly published PoCs or a CISA KEV addition, which would raise priority.
| Microsoft Windows DWM Core Library (Desktop Window Manager) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.