CVE-2026-69775: Windows DWM Core Library Elevation of Privilege Vulnerability
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.
Other sources
Windows DWM Core Library Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7582Patch KB5122880 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33438Patch KB5122871
Event History
Frequently Asked Questions
Which systems are identified as affected?
The affected software listed is Microsoft Windows 11 and Microsoft Windows Server 2025.
What does an attacker need to exploit this issue?
The attacker must be authorized and have low privileges, and exploitation is described as occurring over a network. The attack has high complexity and requires user interaction.
Is there configuration or workaround guidance available here?
No default-configuration status, mitigation, workaround, or fixed-version information is provided in the available data.