← back
CVE-2026-21519

Desktop Window Manager Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 2.4%● KEVCWE-843
Vexday Risk Score
51Attention
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 2.4%KEV simPoC Nuclei Metasploit Patch referenciado
Lifecycle
10 Feb 2026Active exploitation (CISA KEV)
10 Feb 2026Published on NVD
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A flaw in Windows Desktop Window Manager allows an authorized user to gain higher system privileges through type confusion, where the system mishandles data types in memory.

Technical detail

Type confusion vulnerability (CWE-843) in Desktop Window Manager permits local privilege escalation by an authenticated attacker exploiting incompatible type access; requires prior system access and results in elevated privileges.

Summary generated and translated by AI from the official description.
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →