HIGH
CVE-2026-21519
CVSS
7.8
KEV
Description
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Summary dbcve.org
A type confusion vulnerability in the Desktop Window Manager (dwm.exe) allows a locally authorized attacker to elevate privileges to higher permissions. The vulnerability stems from improper type handling when accessing resources, enabling an attacker with initial local access to gain elevated privileges on the affected system.
Mitigation
Apply the Microsoft security update for CVE-2026-21519 via Windows Update or enterprise patch management tools. Prioritize patching systems with direct user access as the attacker requires local authorization.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
2.46%
Probability of exploitation in next 30 days
83.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.