CyberICT

CVE-2026-21519

Microsoft · Published February 10, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Affected Products

  • Windows 10 1607 < 10.0.14393.8868
  • Windows 10 1809 < 10.0.17763.8389
  • Windows 10 21h2 < 10.0.19044.6937
  • Windows 10 22h2 < 10.0.19045.6937

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H