CVE-2026-61932
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privilege
CVSS
7.8
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 11 ago 2026 · Última mod.: 11 ago 2026 · CWE-122 · CWE-843
Sin historial EPSS suficiente todavía.
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-713318.1 ALT—
———Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.6hCVE-2026-703477.8 ALT—
———Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.6hCVE-2026-703457.8 ALT—
———Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.6hCVE-2026-703306.7 MED—
———Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.6hCVE-2026-703046.7 MED—
———Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.6hCVE-2026-701308.4 ALT—
———Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.6h