Cyber Security News

Desktop Window Manager 0-Day Vulnerability Allows Attacker to Elevate Privileges

Microsoft has released urgent security updates to address a critical zero-day vulnerability in the Windows Desktop Window Manager (DWM).

Tracked as CVE-2026-21519, this flaw is currently being exploited in the wild, allowing attackers to gain full control over affected systems.

The Desktop Window Manager (dwm.exe) is a core Windows system process that renders visual effects on your screen.

Such as transparent windows, live taskbar thumbnails, and support for high-resolution monitors.

Because it manages the entire visual interface, it runs continuously in the background on all modern versions of Windows.

This mismatch can cause the program to read or write data to the wrong memory location, leading to crashes or, in this case, security breaches.

In CVE-2026-21519, attackers can abuse this confusion to trick the DWM process into executing malicious code.

Since DWM interacts closely with the operating system’s kernel, successfully exploiting this flaw allows a local attacker to escalate their privileges from a standard user to SYSTEM level.

SYSTEM privileges grant complete administrative control, allowing the attacker to install programs, view or delete data, and create new accounts with full rights.

Microsoft has rated this vulnerability as Important with a CVSS score of 7.8 and patched it in the February security update.

While the attacker requires local access to the machine (meaning they must already be logged in or have compromised a low-level account), the attack is simple and requires no user interaction.

The vulnerability affects a wide range of Windows versions, including:

ProductSupported Versions
Windows 101809, 21H2, 22H2
Windows 1123H2, 24H2, 25H2, 26H1
Windows Server2016, 2019, 2022, 2025

Since this vulnerability is actively being exploited, users and administrators are urged to apply the February 2026 security updates immediately.

The official fix is available through Windows Update and the Microsoft Update Catalog. Preventing this attack requires patching the operating system; there are no known workarounds.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago