CVE-2026-61932
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Summary
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Windows 10 Version 1607 | 10.0.14393.0 < 10.0.14393.9418 | affected |
| Microsoft | Windows 10 Version 1809 | 10.0.17763.0 < 10.0.17763.9115 | affected |
| Microsoft | Windows 10 Version 21H2 | 10.0.19044.0 < 10.0.19044.7663 | affected |
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0 < 10.0.19045.7663 | affected |
| Microsoft | Windows 11 version 23H2 | 10.0.22631.0 < 10.0.22631.7517 | affected |
| Microsoft | Windows 11 Version 23H2 | 10.0.22631.0 < 10.0.22631.7517 | affected |
| Microsoft | Windows Server 2016 | 10.0.14393.0 < 10.0.14393.9418 | affected |
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.14393.0 < 10.0.14393.9418 | affected |
| Microsoft | Windows Server 2019 | 10.0.17763.0 < 10.0.17763.9115 | affected |
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.17763.0 < 10.0.17763.9115 | affected |
| Microsoft | Windows Server 2022 | 10.0.20348.0 < 10.0.20348.5499 | affected |
Weaknesses
- CWE-843: CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
- CWE-122: CWE-122: Heap-based Buffer Overflow
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.