
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25189 is a use-after-free vulnerability in the Windows Desktop Window Manager (DWM) Core Library that allows an authorized local attacker to elevate privileges. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects Windows 10 versions 1809, 21H2, and 22H2, as well as Windows Server 2019 and Windows Server 2022. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free), occurring within the Windows DWM Core Library — the component responsible for compositing the Windows desktop. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to control the freed memory region and redirect execution flow. Exploitation requires only low-level local privileges and no user interaction, with low attack complexity, making it straightforward for an authenticated local user to trigger. No public proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation allows a low-privileged local attacker to escalate to higher privilege levels — potentially SYSTEM — on the affected machine, resulting in high impact to confidentiality, integrity, and availability. An attacker who gains elevated privileges could install malware, access sensitive data, create new accounts, disable security controls, or use the compromised host as a pivot point for lateral movement within a network. Affected systems include Windows 10 (versions 1809, 21H2, 22H2) and Windows Server 2019 and 2022 (Microsoft MSRC).
Microsoft released patches on March 10, 2026, as part of the March 2026 Patch Tuesday update cycle. Organizations should update affected systems to the following minimum build versions: Windows 10 21H2 to 10.0.19044.7058 or later, Windows 10 22H2 to 10.0.19045.7058 or later, Windows 10 1809 to 10.0.17763.8511 or later, Windows Server 2019 to 10.0.17763.8511 or later, and Windows Server 2022 to 10.0.20348.4830 or later. As interim measures, organizations should limit local access privileges, restrict administrative access to authorized personnel only, and monitor for suspicious privilege escalation activity (Microsoft MSRC).
The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Rapid7, Sophos, Zero Day Initiative, and Cybersecurity News, which collectively noted the patch addressed 79–84 vulnerabilities including two zero-days (not this CVE). Security researchers and community members discussed the patch batch on platforms including Bluesky and dev.to, with CVE-2026-25189 noted as a notable local privilege escalation in the DWM component. No specific controversy or exceptional researcher commentary was directed at this individual CVE (Rapid7 Blog, ZDI Blog, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."