Microsoft Windows 11
cpe:2.3:o:microsoft:windows_11:*:*:*:*:*:*:*
A privilege escalation vulnerability has been identified in the Windows Desktop Window Manager (DWM). This out-of-bounds read issue allows an authorized attacker to elevate privileges locally. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2022, 2025, and 2019.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Users can apply the security update for this vulnerability, which is available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5066791, KB5066793, KB5066835, KB5066780, and KB5066586.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.