CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Other sources
Desktop Window Manager Elevation of Privilege Vulnerability
— Microsoft
Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.1575Patch KB5077179 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6649Patch KB5075941 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2149Patch KB5075897 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32370Fixed in 10.0.26100.32313Patch KB5075942 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8868Patch KB5075999 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7840Fixed in 10.0.26100.7781Patch KB5077212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7840Fixed in 10.0.26200.7781Patch KB5077212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6937Patch KB5075912 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6937Patch KB5075912 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4773Fixed in 10.0.20348.4711Patch KB5075943 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8389Patch KB5075904
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21519?
The severity of CVE-2026-21519 is rated as high due to its potential to allow local privilege escalation.
How do I fix CVE-2026-21519?
To fix CVE-2026-21519, apply the latest security updates from Microsoft tailored for your Windows version.
What systems are affected by CVE-2026-21519?
CVE-2026-21519 affects multiple Windows versions, including Windows 10, Windows 11, and Windows Server products.
Can CVE-2026-21519 be exploited remotely?
CVE-2026-21519 is a local privilege escalation vulnerability, thus it cannot be exploited remotely without prior access to the local system.
Is there a patch available for CVE-2026-21519?
Yes, Microsoft has released patches for CVE-2026-21519, which can be downloaded and applied to affected systems.