
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27923 is a use-after-free (UAF) vulnerability in the Windows Desktop Window Manager (DWM) that allows a locally authenticated, low-privileged attacker to elevate privileges to SYSTEM level. Disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2012/2012 R2/2016/2019/2022/2022 23H2, and Windows Server 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free), occurring within the Desktop Window Manager (DWM) — the compositing window manager responsible for rendering the Windows graphical interface. A use-after-free condition arises when DWM accesses memory that has already been freed, allowing an attacker to manipulate that memory region to redirect execution flow and gain elevated privileges. Exploitation requires only low privileges and no user interaction, with the attack vector being local (Microsoft MSRC, Feedly). No public proof-of-concept code has been observed as of the time of disclosure.
Successful exploitation allows a low-privileged local attacker to escalate to SYSTEM-level privileges, resulting in complete compromise of the affected host — including full confidentiality, integrity, and availability impact. This affects a wide range of Microsoft Windows desktop and server operating systems spanning from Windows Server 2012 to Windows Server 2025 and Windows 10 through Windows 11 26H1. An attacker with initial local access could leverage this vulnerability to disable security controls, install persistent malware, access sensitive credentials, or pivot laterally within a network (Microsoft MSRC).
As of the disclosure date, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation (Feedly). The vulnerability has an EPSS score of approximately 0.044%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys scanners have detection coverage for this vulnerability (detection IDs 92369 and 92370) (Feedly).
Microsoft released patches on April 14, 2026, as part of the April 2026 Patch Tuesday update cycle. Administrators should update affected systems to the following minimum build versions: Windows 10 21H2 → 10.0.19044.7184, Windows 10 22H2 → 10.0.19045.7184, Windows 11 23H2 → 10.0.22631.6936, Windows 11 24H2 → 10.0.26100.8246, Windows 11 25H2 → 10.0.26200.8246, Windows 11 26H1 → 10.0.28000.1836, Windows Server 2016 → 10.0.14393.9060, Windows Server 2019 → 10.0.17763.8644, Windows Server 2022 → 10.0.20348.5020, Windows Server 2022 23H2 → 10.0.25398.2274, Windows Server 2025 → 10.0.26100.32690 (Microsoft MSRC). As a compensating control, organizations should enforce the principle of least privilege and restrict local logon access to minimize the pool of potential attackers.
CVE-2026-27923 was covered as part of broader April 2026 Patch Tuesday roundups by several security outlets. BleepingComputer noted it among 167 flaws fixed in the April 2026 update (BleepingComputer). The Zero Day Initiative (ZDI) included it in their April 2026 security update review (ZDI Blog). Rapid7 and Sophos also covered the patch in their respective Patch Tuesday analyses, and SANS ISC published a diary entry referencing the update (Rapid7 Blog, Sophos Blog). Community discussion on Windows forums highlighted the CVSS 7.8 score and local EoP nature of the flaw.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."