HIGH

CVE-2026-21519

Microsoft Windows 10 1607 2026-02-10 CVSS v3.1
CVSS
7.8
KEV

Description

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Summary dbcve.org

A type confusion vulnerability in the Desktop Window Manager (dwm.exe) allows a locally authorized attacker to elevate privileges to higher permissions. The vulnerability stems from improper type handling when accessing resources, enabling an attacker with initial local access to gain elevated privileges on the affected system.

Mitigation

Apply the Microsoft security update for CVE-2026-21519 via Windows Update or enterprise patch management tools. Prioritize patching systems with direct user access as the attacker requires local authorization.

Weakness (CWE)

CWE-843 Type Confusion

EPSS Score

2.46%
Probability of exploitation in next 30 days
83.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE