
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-45637 is a use-after-free (UAF) elevation of privilege vulnerability in the Windows Desktop Window Manager (DWM) Core Library. It allows a locally authenticated attacker with low privileges to escalate to higher system privileges. Affected products include Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2019, Windows Server 2022, and Windows Server 2025. Microsoft disclosed and patched the vulnerability on June 9, 2026, as part of the June 2026 Patch Tuesday update cycle. It carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, Feedly).
The vulnerability is rooted in a use-after-free condition (CWE-416) in the Windows DWM Core Library (dwmcore.dll), where memory is accessed after it has been freed, potentially allowing an attacker to control the freed memory region and redirect execution flow. The attack vector is local, requiring the attacker to already have a low-privileged authenticated session on the target system; no network access or user interaction is needed. Exploitation requires an authorized local user to trigger the UAF condition, likely through crafted interactions with DWM's graphics/compositing subsystem. No public proof-of-concept code has been identified at this time (MSRC Advisory, Feedly).
Successful exploitation allows a low-privileged local attacker to execute arbitrary code with elevated (SYSTEM-level) privileges, resulting in high confidentiality, integrity, and availability impact on the affected host. An attacker who achieves SYSTEM privileges can install malware, access sensitive credentials, disable security controls, and potentially use the compromised host as a pivot point for lateral movement within the network. The scope is limited to the affected system (unchanged scope), but the full compromise of the local machine represents a significant risk in multi-user or shared environments (Feedly, MSRC Advisory).
Microsoft released patches for all affected Windows versions as part of the June 9, 2026 Patch Tuesday update. Organizations should apply the following updates immediately:
As a defense-in-depth measure, enforce the principle of least privilege to limit local user access and reduce the attack surface. No vendor-documented workaround exists as a substitute for patching (MSRC Advisory, Feedly).
CVE-2026-45637 was covered as part of broader reporting on Microsoft's June 2026 Patch Tuesday, which addressed approximately 200 vulnerabilities including multiple zero-days. Security outlets such as BleepingComputer, Rapid7, Zero Day Initiative (ZDI), Sophos, and GBHackers reported on the overall patch batch, with this specific DWM UAF flaw noted among the elevation of privilege issues. No specific researcher commentary or social media discussion focused exclusively on this CVE has been identified (BleepingComputer, ZDI, Rapid7).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."