CVE-2026-34336: Windows DWM Core Library Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Other sources
Windows DWM Core Library Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7219Patch KB5093998 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8457Fixed in 10.0.26200.8390Patch KB5089466 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7079Patch KB5087420 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7291Patch KB5087544 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2330Patch KB5087541 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7417Patch KB5094127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32860Fixed in 10.0.26100.32772Patch KB5087423 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5139Fixed in 10.0.20348.5074Patch KB5087424 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9140Patch KB5087537 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8755Patch KB5087538 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2113Patch KB5089548 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8457Fixed in 10.0.26100.8390Patch KB5089466
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34336?
CVE-2026-34336 is rated as a medium severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2026-34336?
To fix CVE-2026-34336, you should apply the latest patches provided by Microsoft for your affected Windows version.
What versions of Windows are affected by CVE-2026-34336?
CVE-2026-34336 affects multiple versions of Windows including Windows 11 and Windows Server 2022, among others.
Can CVE-2026-34336 be exploited remotely?
CVE-2026-34336 requires local access, meaning it cannot be exploited remotely.
What type of information can be disclosed due to CVE-2026-34336?
CVE-2026-34336 may allow an attacker to disclose sensitive information from the affected system.