cbcvebase.
CVE-2026-42896
published 2026-05-12

CVE-2026-42896: Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftwindows_11_24h2< 10.0.26100.845710.0.26100.8457
microsoftwindows_11_25h2< 10.0.26200.845710.0.26200.8457
microsoftwindows_11_26h1< 10.0.28000.211310.0.28000.2113
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.845710.0.26100.8457
microsoftwindows_11_version_25h2>= 10.0.26200.0 < 10.0.26200.845710.0.26200.8457
microsoftwindows_11_version_26h1>= 10.0.28000.0 < 10.0.28000.211310.0.28000.2113
microsoftwindows_server_2025< 10.0.26100.3286010.0.26100.32860
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.3286010.0.26100.32860