CVE-2026-25189
vulnerability analysis and mitigation

Overview

CVE-2026-25189 is a use-after-free vulnerability in the Windows Desktop Window Manager (DWM) Core Library that allows an authorized local attacker to elevate privileges. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects Windows 10 versions 1809, 21H2, and 22H2, as well as Windows Server 2019 and Windows Server 2022. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within the Windows DWM Core Library — the component responsible for compositing the Windows desktop. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to control the freed memory region and redirect execution flow. Exploitation requires only low-level local privileges and no user interaction, with low attack complexity, making it straightforward for an authenticated local user to trigger. No public proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).

Impact

Successful exploitation allows a low-privileged local attacker to escalate to higher privilege levels — potentially SYSTEM — on the affected machine, resulting in high impact to confidentiality, integrity, and availability. An attacker who gains elevated privileges could install malware, access sensitive data, create new accounts, disable security controls, or use the compromised host as a pivot point for lateral movement within a network. Affected systems include Windows 10 (versions 1809, 21H2, 22H2) and Windows Server 2019 and 2022 (Microsoft MSRC).

Mitigation and workarounds

Microsoft released patches on March 10, 2026, as part of the March 2026 Patch Tuesday update cycle. Organizations should update affected systems to the following minimum build versions: Windows 10 21H2 to 10.0.19044.7058 or later, Windows 10 22H2 to 10.0.19045.7058 or later, Windows 10 1809 to 10.0.17763.8511 or later, Windows Server 2019 to 10.0.17763.8511 or later, and Windows Server 2022 to 10.0.20348.4830 or later. As interim measures, organizations should limit local access privileges, restrict administrative access to authorized personnel only, and monitor for suspicious privilege escalation activity (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Rapid7, Sophos, Zero Day Initiative, and Cybersecurity News, which collectively noted the patch addressed 79–84 vulnerabilities including two zero-days (not this CVE). Security researchers and community members discussed the patch batch on platforms including Bluesky and dev.to, with CVE-2026-25189 noted as a notable local privilege escalation in the DWM component. No specific controversy or exceptional researcher commentary was directed at this individual CVE (Rapid7 Blog, ZDI Blog, Sophos Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management