Microsoft DWM Core Library是美国Microsoft公司的一个windows的核心库。 Microsoft DWM Core Library 存在缓冲区错误漏洞,该漏洞源于Windows DWM Core Library存在越界读取,可能导致授权攻击者在本地泄露信息。以下产品及版本受到影响:Windows 11 Version 24H2 10.0.26100.0至10.0.26100.9168之前版本、Windows 11 Version 25H2 10.0.26200.0至10.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Windows 11 Version 24H2 | 10.0.26100.0< 10.0.26100.9168 |
affected |
| Microsoft | Windows 11 Version 25H2 | 10.0.26200.0< 10.0.26200.9168 |
affected |
| Microsoft | Windows 11 version 26H1 | 10.0.28000.0< 10.0.28000.2704 |
affected |
| Microsoft | Windows Server 2025 | 10.0.26100.0< 10.0.26100.33296 |
affected |
| Microsoft | Windows Server 2025 (Server Core installation) | 10.0.26100.0< 10.0.26100.33296 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Windows 11 Version 24H2 | 10.0.26100.0 ~ 10.0.26100.9168 | - |
|
| Microsoft | Windows 11 Version 25H2 | 10.0.26200.0 ~ 10.0.26200.9168 | - |
|
| Microsoft | Windows 11 version 26H1 | 10.0.28000.0 ~ 10.0.28000.2704 | - |
|
| Microsoft | Windows Server 2025 | 10.0.26100.0 ~ 10.0.26100.33296 | - |
|
| Microsoft | Windows Server 2025 (Server Core installation) | 10.0.26100.0 ~ 10.0.26100.33296 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62878 | 9.8 CRITICAL | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-65791 | 9.8 CRITICAL | Windows iSCSI Target Service Remote Code Execution Vulnerability |
| CVE-2026-59124 | 9.8 CRITICAL | Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability |
| CVE-2026-62893 | 9.8 CRITICAL | Windows Deployment Services TFTP Server Remote Code Execution Vulnerability |
| CVE-2026-62815 | 9.8 CRITICAL | Microsoft QUIC Remote Code Execution Vulnerability |
| CVE-2026-50516 | 9.4 CRITICAL | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
| CVE-2026-70306 | 9.3 CRITICAL | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-70329 | 8.8 HIGH | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2026-65665 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-62824 | 8.8 HIGH | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-62822 | 8.8 HIGH | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-62872 | 8.8 HIGH | .NET Framework Elevation of Privilege Vulnerability |
| CVE-2026-65767 | 8.8 HIGH | Microsoft Teams for Android Spoofing Vulnerability |
| CVE-2026-65663 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-65658 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-70336 | 8.8 HIGH | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-62790 | 8.8 HIGH | Windows SMBv3 Server Remote Code Execution Vulnerability |
| CVE-2026-62800 | 8.8 HIGH | Windows SMBv3 Server Remote Code Execution Vulnerability |
| CVE-2026-69320 | 8.8 HIGH | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-66808 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
Showing top 20 of 402 CVEs. View all on vendor page → →
No comments yet