CVE-2026-61932

Summary

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Affected Software

VendorProductVersion RangeStatus
MicrosoftWindows 10 Version 160710.0.14393.0 < 10.0.14393.9418affected
MicrosoftWindows 10 Version 180910.0.17763.0 < 10.0.17763.9115affected
MicrosoftWindows 10 Version 21H210.0.19044.0 < 10.0.19044.7663affected
MicrosoftWindows 10 Version 22H210.0.19045.0 < 10.0.19045.7663affected
MicrosoftWindows 11 version 23H210.0.22631.0 < 10.0.22631.7517affected
MicrosoftWindows 11 Version 23H210.0.22631.0 < 10.0.22631.7517affected
MicrosoftWindows Server 201610.0.14393.0 < 10.0.14393.9418affected
MicrosoftWindows Server 2016 (Server Core installation)10.0.14393.0 < 10.0.14393.9418affected
MicrosoftWindows Server 201910.0.17763.0 < 10.0.17763.9115affected
MicrosoftWindows Server 2019 (Server Core installation)10.0.17763.0 < 10.0.17763.9115affected
MicrosoftWindows Server 202210.0.20348.0 < 10.0.20348.5499affected

Weaknesses

  • CWE-843: CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
  • CWE-122: CWE-122: Heap-based Buffer Overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References