cbcvebase.
CVE-2026-32152
published 2026-04-14

CVE-2026-32152: Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Affected

7 ranges
VendorProductVersion rangeFixed in
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.693610.0.22631.6936
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.693610.0.22631.6936
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.824610.0.26100.8246
microsoftwindows_11_version_25h2>= 10.0.26200.0 < 10.0.26200.824610.0.26200.8246
microsoftwindows_11_version_26h1>= 10.0.28000.0 < 10.0.28000.183610.0.28000.1836
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.502010.0.20348.5020
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.3269010.0.26100.32690