CVE-2026-45637
vulnerability analysis and mitigation

Overview

CVE-2026-45637 is a use-after-free (UAF) elevation of privilege vulnerability in the Windows Desktop Window Manager (DWM) Core Library. It allows a locally authenticated attacker with low privileges to escalate to higher system privileges. Affected products include Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2019, Windows Server 2022, and Windows Server 2025. Microsoft disclosed and patched the vulnerability on June 9, 2026, as part of the June 2026 Patch Tuesday update cycle. It carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, Feedly).

Technical details

The vulnerability is rooted in a use-after-free condition (CWE-416) in the Windows DWM Core Library (dwmcore.dll), where memory is accessed after it has been freed, potentially allowing an attacker to control the freed memory region and redirect execution flow. The attack vector is local, requiring the attacker to already have a low-privileged authenticated session on the target system; no network access or user interaction is needed. Exploitation requires an authorized local user to trigger the UAF condition, likely through crafted interactions with DWM's graphics/compositing subsystem. No public proof-of-concept code has been identified at this time (MSRC Advisory, Feedly).

Impact

Successful exploitation allows a low-privileged local attacker to execute arbitrary code with elevated (SYSTEM-level) privileges, resulting in high confidentiality, integrity, and availability impact on the affected host. An attacker who achieves SYSTEM privileges can install malware, access sensitive credentials, disable security controls, and potentially use the compromised host as a pivot point for lateral movement within the network. The scope is limited to the affected system (unchanged scope), but the full compromise of the local machine represents a significant risk in multi-user or shared environments (Feedly, MSRC Advisory).

Mitigation and workarounds

Microsoft released patches for all affected Windows versions as part of the June 9, 2026 Patch Tuesday update. Organizations should apply the following updates immediately:

  • Windows 10 1809 / Server 2019: Update to build 10.0.17763.8880 or later
  • Windows 10 21H2: Update to build 10.0.19044.7417 or later
  • Windows 10 22H2: Update to build 10.0.19045.7417 or later
  • Windows 11 23H2: Update to build 10.0.22631.7219 or later
  • Windows 11 24H2: Update to build 10.0.26100.8655 or later
  • Windows 11 25H2: Update to build 10.0.26200.8655 or later
  • Windows 11 26H1: Update to build 10.0.28000.2269 or later
  • Windows Server 2022: Update to build 10.0.20348.5256 or later
  • Windows Server 2025: Update to build 10.0.26100.32995 or later

As a defense-in-depth measure, enforce the principle of least privilege to limit local user access and reduce the attack surface. No vendor-documented workaround exists as a substitute for patching (MSRC Advisory, Feedly).

Community reactions

CVE-2026-45637 was covered as part of broader reporting on Microsoft's June 2026 Patch Tuesday, which addressed approximately 200 vulnerabilities including multiple zero-days. Security outlets such as BleepingComputer, Rapid7, Zero Day Initiative (ZDI), Sophos, and GBHackers reported on the overall patch batch, with this specific DWM UAF flaw noted among the elevation of privilege issues. No specific researcher commentary or social media discussion focused exclusively on this CVE has been identified (BleepingComputer, ZDI, Rapid7).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management