Description
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Elevation of Privilege
Action: Patch
AI Analysis

Impact

The reported use‑after‑free flaw exists in the Windows Desktop Window Manager (DWM) Core Library. When the library frees a memory region and subsequently reuses it in an incorrect manner, an authorized attacker can execute arbitrary code with elevated privileges. The vulnerability allows privilege escalation for an attacker who already has some level of access to the target system and can exploit the DWM subsystem over a network connection.

Affected Systems

Microsoft Windows 11 Version 23H2 (both x64 and arm64 builds) and Microsoft Windows Server 2025, including Server Core installations, are affected as listed in the security advisory. The flaw is active whenever the DWM Core Library is loaded on those versions.

Risk and Exploitability

The CVSS score is 7.1, reflecting moderate severity, while the EPSS score is below 1%, indicating a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to be authorized or have locally elevated access to the machine so that the use‑after‑free condition can be triggered, typically through a privileged network session or a compromised user account with sufficient rights to interact with DWM.

Generated by OpenCVE AI on September 10, 2026 at 01:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for Windows 11 23H2 and Windows Server 2025 that addresses CVE‑2026‑69775.
  • Apply network segmentation or isolation policies to limit privileged network communications until the patch is deployed.
  • Continuously monitor Microsoft advisories for related mitigations and follow any additional guidance issued by Microsoft.

Generated by OpenCVE AI on September 10, 2026 at 01:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 23h2
Microsoft windows Server 2025 (server Core Installation)

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.
Title Windows DWM Core Library Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:07.062Z

Reserved: 2026-08-03T22:46:09.552Z

Link: CVE-2026-69775

cve-icon Vulnrichment

Updated: 2026-09-09T19:09:40.498Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:48.980

Modified: 2026-09-22T19:53:05.127

Link: CVE-2026-69775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:08:57Z

Weaknesses