Microsoft Windows DWM Core Library Privilege Escalation Vulnerability
Vulnerability
A heap-based buffer overflow vulnerability has been identified in the Windows DWM Core Library. This vulnerability allows an authorized attacker to elevate privileges locally. The issue affects multiple Windows products and versions, including Windows 10, Windows 11, Windows Server 2019, and Windows Server 2022.
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Remediation
Users can apply the security update KB5066791 for Windows 10, KB5066835 for Windows 11, and KB5066782 for Windows Server 2022. For Windows Server 2019, the security update is also KB5066586.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
