← back
CVE-2026-21519

Desktop Window Manager Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 2.4%● KEVCWE-843
In short

A flaw in Windows Desktop Window Manager allows an authorized user to gain higher system privileges through type confusion, where the system mishandles data types in memory.

Technical detail

Type confusion vulnerability (CWE-843) in Desktop Window Manager permits local privilege escalation by an authenticated attacker exploiting incompatible type access; requires prior system access and results in elevated privileges.

Summary generated and translated by AI from the official description.
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →