CVE-2026-32152
vulnerability analysis and mitigation

Overview

CVE-2026-32152 is a use-after-free (UAF) vulnerability in the Windows Desktop Window Manager (DWM) that allows a locally authenticated attacker to elevate privileges. Disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday, it affects Windows 11 (versions 23H2, 24H2, 25H2, 26H1) and Windows Server 2022/2025. It carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within the Desktop Window Manager (DWM) component of Windows. A use-after-free condition arises when freed memory is subsequently referenced or reused, potentially allowing an attacker to control execution flow or corrupt memory in a privileged context. Exploitation requires only low-level user privileges and no user interaction, making it a straightforward local privilege escalation path. No public technical write-ups or proof-of-concept code detailing the specific DWM code path have been published as of the time of disclosure (MSRC Advisory, GitHub Advisory).

Impact

Successful exploitation allows a low-privileged local attacker to escalate to SYSTEM-level privileges, resulting in complete compromise of the affected Windows system. This enables unauthorized data theft, modification of system configurations, installation of persistent malware, and potential lateral movement within a network if the compromised system has access to shared resources or credentials. All three security pillars — confidentiality, integrity, and availability — are rated High impact (MSRC Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (MSRC Advisory). The EPSS score is approximately 0.044–0.057%, placing it in the lower percentiles for near-term exploitation likelihood (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Mitigation and workarounds

Microsoft released security updates on April 14, 2026, addressing this vulnerability across all affected products. Administrators should apply the following patched builds: Windows 11 23H2 → 10.0.22631.6936, Windows 11 24H2/25H2 → 10.0.26100.32690 / 10.0.26200.8246, Windows 11 26H1 → 10.0.28000.1836, Windows Server 2022 → 10.0.20348.5020, Windows Server 2022 23H2 → 10.0.25398.2274, Windows Server 2025 → 10.0.26100.32690. As a defense-in-depth measure, organizations should enforce the principle of least privilege to limit the number of accounts that could leverage this flaw, and monitor for anomalous privilege escalation activity (MSRC Advisory).

Community reactions

The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by multiple security outlets. BleepingComputer reported on the full April 2026 update fixing 167 flaws, while Qualys, Rapid7, Talos Intelligence, Sophos, and Zero Day Initiative each published Patch Tuesday review blogs that included CVE-2026-32152 among notable DWM and privilege escalation issues (BleepingComputer, Qualys Blog, ZDI Blog). No specific researcher commentary singling out this CVE has been identified beyond standard Patch Tuesday coverage.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management