CVE-2026-35419Patch(microsoft / windows_11_24h2)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_11_24h2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_24h2
  • windows_11_25h2
  • windows_11_26h1
  • windows_server_2025

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2025

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-25: 1Mentions · 2026-07-02: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-25: 1Technical Details · 2026-07-02: 105-1205-2507-02
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
Disclosure1
2026-05-251
Patch1
2026-07-021
Patch1
Full discourse3 posts
  • immortalp0ny@immortalp0ny
    Patch

    Finally advisories for vulns that I found in dwmcore.dll were fixed (CVE-2026-34336, CVE-2026-35419). However, for CVE-2026-34336 list of CWE is not accurate cause heap-based overflow is possible due to integer overflow and integer overflow is possible due SubChannelMaskInfo abuse.

    Post summary

    The post reports that advisories for CVE-2026-34336 and CVE-2026-35419 have been fixed, mentions remediation availability, and provides a brief technical description of the heap-based overflow vulnerability.

    120811.5K
    926 followersView on X
  • Positive Technologies Global@PTsecurity_EN
    Patch

    Two Windows DWM 0-days patched 🚨 CVE-2026-35419 & CVE-2026-34336. Sergey Tarasov (PT ESC) caught them in dwmcore.dll. Initial access + these bugs = full device control. Patches are out. Update ASAP. Details ↓ https://dbugs.ptsecurity.com/vulnerability/PT-2026-40155?utm_source=x&utm_medium=msft&utm_campaign=17_06 #0day #Windows https://t.co/lwVl1Iqigi

    Post summary

    The tweet announces that patches for two Windows DWM 0‑day vulnerabilities (CVE-2026-35419 & CVE-2026-34336) are available and urges immediate update, but does not provide a PoC or exploitation details.

    00011414
    3.6K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 DWM info disclosure (CVE-2026-35419) is Microsoft’s way of saying “no RCE, but hey—spying on your desktop plumbing.” Why it matters: attackers love data, not just shells. #Windows #Security https://windowsforum.com/threads/cve-2026-35419-dwm-info-disclosure-why-microsoft-s-report-confidence-matters.417795/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #InformationDisclosure #SecurityUpdateGuide #WindowsDwm https://t.co/SNZiRSC3Hi

    Post summary

    Microsoft disclosed CVE‑2026‑35419 as an information‑disclosure flaw that does not provide remote code execution but could be leveraged for spying on desktop activity.

    0000047
    1.1K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2025---

Explore more