Impact
A type‑confusion flaw in the Windows Desktop Window Manager (DWM) core library allows a user with local execution rights to use an incompatible data type to access a protected resource, thereby elevating privileges. The defect is a classic implementation error that can lead to privileges beyond those user’s original rights, matching CWE‑843. Victims can gain local system privileges by feeding crafted input to a DWM service that expects a different data type.
Affected Systems
Microsoft Windows 10 builds 1607, 1809, 21H2, and 22H2; Windows 11 builds 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025, both in default installations and in Server Core configurations, are affected.
Risk and Exploitability
The CVSS base score of 7.8 indicates high severity, while the EPSS score of less than 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a user with local privileges who can run or install software; based on the description it is inferred that an attacker would need the ability to execute code as a local user to trigger the type‑confusion. If such code runs under elevated or delegated contexts, the attacker can gain system‑level privileges on the host.
OpenCVE Enrichment