CVE-2026-21519
vulnerability analysis and mitigation

Overview

CVE-2026-21519 is a type confusion (CWE-843) vulnerability in the Windows Desktop Window Manager (DWM) that allows an authenticated attacker with low-level privileges to escalate privileges locally. Disclosed on February 10, 2026, as part of Microsoft's February Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, 2022 23H2, and 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, CISA KEV).

Technical details

The vulnerability is rooted in how the Desktop Window Manager accesses resources using incompatible types — a classic type confusion flaw classified as CWE-843. An attacker who has already obtained low-privilege authenticated access to a Windows system can trigger this flaw locally, without requiring user interaction, to gain SYSTEM-level privileges. The attack vector is local (AV:L), with low attack complexity and low privilege requirements, making it straightforward to exploit once initial access is established. No public proof-of-concept exploit code has been identified, though active in-the-wild exploitation has been confirmed (Microsoft MSRC, CISA KEV).

Impact

Successful exploitation allows an attacker to escalate from a low-privilege authenticated account to SYSTEM-level access, enabling complete system compromise. This includes arbitrary code execution, malware installation, credential theft, and potential lateral movement across the network. The broad scope of affected products — spanning all supported Windows 10, Windows 11, and Windows Server versions — significantly amplifies the potential attack surface (Microsoft MSRC, CISA KEV).

Exploitation steps

  1. Initial Access: Obtain low-privilege authenticated access to a target Windows system (e.g., via phishing, credential theft, or exploitation of another vulnerability).
  2. Reconnaissance: Confirm the target is running a vulnerable Windows version (Windows 10 1607/1809/21H2/22H2, Windows 11 23H2/24H2/25H2/26H1, or Windows Server 2016/2019/2022/2022 23H2/2025) and has not applied the February 2026 security update.
  3. Trigger Type Confusion: Execute a crafted payload targeting the Desktop Window Manager (dwm.exe) that causes it to access a resource using an incompatible type, exploiting the CWE-843 flaw.
  4. Privilege Escalation: Leverage the type confusion to gain SYSTEM-level code execution within the DWM process context.
  5. Post-Exploitation: With SYSTEM privileges, deploy malware, harvest credentials, disable security controls, or move laterally across the network (Microsoft MSRC, CISA KEV).

Indicators of compromise

  • Process: Unusual child processes spawned by dwm.exe (Desktop Window Manager), such as cmd.exe, powershell.exe, or other administrative tools running under the SYSTEM account unexpectedly.
  • Logs: Windows Security Event Log entries showing privilege escalation (Event ID 4672 – Special privileges assigned to new logon) for accounts that should not hold SYSTEM-level rights; unexpected logon events (Event ID 4624) with elevated tokens.
  • File System: New or modified executables, scripts, or scheduled tasks created by the SYSTEM account in unusual directories (e.g., %TEMP%, %APPDATA%, or system directories) shortly after a low-privilege user session.
  • Network: Outbound connections from dwm.exe or newly spawned SYSTEM-level processes to external or unusual internal IP addresses, potentially indicating C2 communication or lateral movement.

Mitigation and workarounds

Microsoft released patches on February 10, 2026, as part of the February Patch Tuesday update. Affected systems should be updated to the following minimum versions: Windows 10 21H2 (10.0.19044.6937), Windows 10 22H2 (10.0.19045.6937), Windows 10 1809 (10.0.17763.8389), Windows 10 1607 (10.0.14393.8868), Windows 11 23H2 (10.0.22631.6649), Windows 11 24H2 (10.0.26100.7781), Windows 11 25H2 (10.0.26200.7781), Windows Server 2016 (10.0.14393.8868), Windows Server 2019 (10.0.17763.8389), Windows Server 2022 (10.0.20348.4711), Windows Server 2022 23H2 (10.0.25398.2149), and Windows Server 2025 (10.0.26100.32313). Given confirmed active exploitation and CISA KEV listing, immediate patching is critical; no alternative workarounds have been published (Microsoft MSRC, CISA KEV).

Community reactions

The February 2026 Patch Tuesday release, which included CVE-2026-21519 alongside five other actively exploited zero-days, drew significant attention from the security community. Researchers at Tenable, Qualys, Rapid7, CrowdStrike, and Sophos all highlighted the DWM vulnerability as a high-priority patch given its active exploitation status and broad Windows version coverage. Forbes and other mainstream outlets ran headlines such as "Microsoft Confirms Windows Is Under Attack — Update Now," reflecting the urgency of the disclosure. CRN noted that security researchers described the number of zero-days in this release as "extraordinarily high." CISA's same-day addition of six Microsoft CVEs to the KEV catalog underscored the severity of the situation (Tenable Blog, CISA Alert).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management