
Finally advisories for vulns that I found in dwmcore.dll were fixed (CVE-2026-34336, CVE-2026-35419). However, for CVE-2026-34336 list of CWE is not accurate cause heap-based overflow is possible due to integer overflow and integer overflow is possible due SubChannelMaskInfo abuse.
Post summary
The text informs that advisories for CVE‑2026‑34336 and CVE‑2026‑35419 have been fixed, noting specific technical details of the vulnerabilities.


