
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21519 is a type confusion (CWE-843) vulnerability in the Windows Desktop Window Manager (DWM) that allows an authenticated attacker with low-level privileges to escalate privileges locally. Disclosed on February 10, 2026, as part of Microsoft's February Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, 2022 23H2, and 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, CISA KEV).
The vulnerability is rooted in how the Desktop Window Manager accesses resources using incompatible types — a classic type confusion flaw classified as CWE-843. An attacker who has already obtained low-privilege authenticated access to a Windows system can trigger this flaw locally, without requiring user interaction, to gain SYSTEM-level privileges. The attack vector is local (AV:L), with low attack complexity and low privilege requirements, making it straightforward to exploit once initial access is established. No public proof-of-concept exploit code has been identified, though active in-the-wild exploitation has been confirmed (Microsoft MSRC, CISA KEV).
Successful exploitation allows an attacker to escalate from a low-privilege authenticated account to SYSTEM-level access, enabling complete system compromise. This includes arbitrary code execution, malware installation, credential theft, and potential lateral movement across the network. The broad scope of affected products — spanning all supported Windows 10, Windows 11, and Windows Server versions — significantly amplifies the potential attack surface (Microsoft MSRC, CISA KEV).
dwm.exe (Desktop Window Manager), such as cmd.exe, powershell.exe, or other administrative tools running under the SYSTEM account unexpectedly.%TEMP%, %APPDATA%, or system directories) shortly after a low-privilege user session.dwm.exe or newly spawned SYSTEM-level processes to external or unusual internal IP addresses, potentially indicating C2 communication or lateral movement.Microsoft released patches on February 10, 2026, as part of the February Patch Tuesday update. Affected systems should be updated to the following minimum versions: Windows 10 21H2 (10.0.19044.6937), Windows 10 22H2 (10.0.19045.6937), Windows 10 1809 (10.0.17763.8389), Windows 10 1607 (10.0.14393.8868), Windows 11 23H2 (10.0.22631.6649), Windows 11 24H2 (10.0.26100.7781), Windows 11 25H2 (10.0.26200.7781), Windows Server 2016 (10.0.14393.8868), Windows Server 2019 (10.0.17763.8389), Windows Server 2022 (10.0.20348.4711), Windows Server 2022 23H2 (10.0.25398.2149), and Windows Server 2025 (10.0.26100.32313). Given confirmed active exploitation and CISA KEV listing, immediate patching is critical; no alternative workarounds have been published (Microsoft MSRC, CISA KEV).
The February 2026 Patch Tuesday release, which included CVE-2026-21519 alongside five other actively exploited zero-days, drew significant attention from the security community. Researchers at Tenable, Qualys, Rapid7, CrowdStrike, and Sophos all highlighted the DWM vulnerability as a high-priority patch given its active exploitation status and broad Windows version coverage. Forbes and other mainstream outlets ran headlines such as "Microsoft Confirms Windows Is Under Attack — Update Now," reflecting the urgency of the disclosure. CRN noted that security researchers described the number of zero-days in this release as "extraordinarily high." CISA's same-day addition of six Microsoft CVEs to the KEV catalog underscored the severity of the situation (Tenable Blog, CISA Alert).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."