CVE-2026-61932: Windows DWM Core Library Elevation of Privilege Vulnerability
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Other sources
Windows DWM Core Library Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7517Patch KB5120240 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7663Patch KB5120249 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7663Patch KB5120249 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9418Patch KB5120418 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5499Fixed in 10.0.20348.5440Patch KB5120229 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9115Patch KB5120238
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61932?
The severity of CVE-2026-61932 is rated high with a CVSS score of 7.8.
How do I fix CVE-2026-61932?
To fix CVE-2026-61932, you should apply the latest security updates provided by Microsoft for your affected Windows version.
What systems are affected by CVE-2026-61932?
CVE-2026-61932 affects Microsoft Windows 10, Windows 11, and Windows Server 2016, 2019, and 2022.
What type of vulnerability is CVE-2026-61932?
CVE-2026-61932 is classified as an Elevation of Privilege vulnerability due to type confusion in the Windows DWM Core Library.
Can CVE-2026-61932 be exploited remotely?
CVE-2026-61932 cannot be exploited remotely, as it requires local access for an authorized attacker to elevate privileges.