Microsoft addressed CVE-2026-20805, a Windows Desktop Window Manager (DWM) vulnerability, in its January 2026 security updates. Patch analysis identified a use-after-free condition in dwmcore.dll: the CSynchronousSuperWetInk destructor could free an object while CSuperWetInkManager retained a reference, leaving a dangling pointer for later use during DWM rendering.
A low-privileged application can reportedly trigger the flaw through DirectComposition and reclaim the released heap allocation, potentially achieving code execution in the DWM process at SYSTEM integrity. Microsoft corrected the object-lifetime handling by conditionally enabling feature flag Feature_1732988217, which ensures RemoveSource() is called; organizations should apply the January 2026 Windows security updates across supported endpoints.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft addressed a use-after-free flaw in the Windows Desktop Window Manager's dwmcore.dll during the January 2026 Patch Tuesday release. The fix adds Feature_1732988217 and unconditionally removes the object from CSuperWetInkManager during destruction, preventing a stale pointer from being retained.
Elastic Security Labs analyzed the vulnerable and patched DWM binaries and described how a low-privileged application could trigger the DirectComposition flaw, reclaim the freed allocation, and execute code in dwm.exe at System integrity. The analysis identified vulnerable version 10.0.26100.7309 and patched version 10.0.26100.7623.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourcelearn.microsoft.com
Open sourceibm.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.