CVE-2026-32152 is a use-after-free vulnerability in Desktop Window Manager that permits authorized local attackers to elevate their privileges on affected systems. This vulnerability affects Windows desktop environments and exploits memory management weaknesses in the graphical subsystem. The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH) with a local attack vector requiring low complexity and low privileges, resulting in high impact across confidentiality, integrity, and availability. No user interaction is required for exploitation, making it a straightforward privilege escalation path for authenticated users. Currently, there is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list and remains inactive on threat intelligence hot lists. With an EPSS score of 0.00049 and a FAUCET risk score of 39.0 out of 100, the immediate exploitation probability remains relatively low, though organizations should prioritize patching given the privilege escalation capability and the low barrier to exploitation for local users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.22631.6936CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.22631.6936CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:* | ||
< 10.0.26100.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.26100.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* | ||
< 10.0.26200.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.