Description
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Published: 2026-07-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an out‑of‑bounds read in the Windows Desktop Window Manager (DWM) core library that allows an attacker with local authorization to trigger an out‑of‑bounds memory read and expose sensitive data stored in process memory. The identified weakness is CWE‑125, representing an attempt to access memory beyond legitimate bounds. The incident could reveal non‑privileged user data or other information resident in the victim’s memory space.

Affected Systems

Affected operating systems include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025, both in full and Server Core installations. The data indicates that systems running the specified architectures (x86, x64, arm64) are vulnerable, as enumerated in the associated CPE strings.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity for an information‑disclosure weakness. The EPSS score is reported as less than 1 %, suggesting that exploitation is not widespread and likely requires a local attacker. The vulnerability is not listed in CISA’s KEV catalog, indicating no known large‑scale exploitation. The attack vector is inferred to require local, authorized user privileges, and the flaw does not provide remote code execution or privilege escalation on its own.

Generated by OpenCVE AI on August 1, 2026 at 09:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update that fixes CVE-2026-50437 for your Windows 10/11/Server revision (details at the MSRC link).
  • Reboot the system after applying the update to ensure the patched DWM core library is loaded.
  • If the update cannot be applied immediately, reduce local user privileges to prevent execution of the DWM core library or disable unnecessary DWM features via group policy until a patch becomes available.

Generated by OpenCVE AI on August 1, 2026 at 09:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Title Windows DWM Core Library Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:24:44.714Z

Reserved: 2026-06-04T18:57:47.376Z

Link: CVE-2026-50437

cve-icon Vulnrichment

Updated: 2026-07-15T13:05:19.250Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:45:03Z

Weaknesses