CVE-2026-62888
Windows DWM Core Library Elevation of Privilege Vulnerability
Description
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-62888 is a Windows flaw that can let a local attacker gain higher privileges on affected versions; small businesses should act by updating Windows to the listed fixed releases.
CVE-2026-62888 is a Windows DWM Core Library elevation-of-privilege issue caused by a use-after-free condition (CWE-416) that can be triggered by an authorized local attacker to elevate privileges on Windows 10, Windows 11, and Windows Server 2022/2025.
What to do now
- Check which Windows versions you run (Windows 10/11, Windows Server 2022/2025) and record their exact build numbers.
- Compare your build to the fixed versions below; if you match any affected build, plan an update immediately.
- Apply the vendor security update for CVE-2026-62888 (via Windows Update / Microsoft update catalog / your patch management process).
- Recheck the system build number after patching to confirm it is now at or above the fixed release for your Windows edition.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62888 and every CVE in our database. Create a free account — no credit card required.
Create Free Account