Microsoft Windows DWM Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in the Windows Desktop Window Manager (DWM). This out-of-bounds read issue allows an authorized attacker to elevate privileges locally. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2022, 2025, and 2019.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.

Remediation

Users can apply the security update for this vulnerability, which is available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5066791, KB5066793, KB5066835, KB5066780, and KB5066586.

Added: Oct 14, 2025, 7:51 PM
Updated: Oct 14, 2025, 7:51 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.