Description
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorized local attacker can exploit a use‑after‑free bug in the Desktop Window Manager (DWM) to elevate privileges. The vulnerability is a memory safety error classified as CWE‑416. The flaw may allow a user who can run code within the victim’s session to obtain higher privileges on the affected machine.

Affected Systems

Microsoft Windows 11, 26H1, 64‑bit build. This is the only product listed as affected.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity that local privilege escalation is possible. The EPSS score is below 1 % so the chance of spontaneous exploitation is low, and the vulnerability is not listed in CISA KEV. The attack vector requires an authorized attacker with local access, which means it cannot be exploited remotely. However, for environments where local users have extensive privileges or where workstations are not properly fenced, the risk is non‑negligible.

Generated by OpenCVE AI on July 31, 2026 at 06:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft update that patches CVE-2026-58634
  • Configure Windows Update to automatically install future security patches
  • Limit local user privileges and enforce least‑privilege principles to reduce the impact if the flaw were exploited

Generated by OpenCVE AI on July 31, 2026 at 06:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Title Desktop Window Manager Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 26h1
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:59:02.967Z

Reserved: 2026-07-01T21:14:44.617Z

Link: CVE-2026-58634

cve-icon Vulnrichment

Updated: 2026-07-14T17:48:46.503Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:15:04Z

Weaknesses