CVE-2023-36033 is a use-after-free vulnerability in the Windows Desktop Window Manager (DWM) Core Library. A local attacker can exploit DWM's exposure to interactions from lower-privileged user contexts to execute attacker-controlled shellcode within the high-integrity DWM process running under the Window Manager\DWM identity. Observed exploitation further abused DirectComposition object marshaling between DWM and the Windows logon UI process to induce loading of an attacker-controlled DLL by a SYSTEM-level process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows Desktop Window Manager (DWM) elevation of privilege vulnerability referenced as having been exploited as a zero-day in 2023.
A Windows Desktop Window Manager (DWM) Core Library elevation-of-privilege vulnerability that was previously a zero-day and was exploited in the wild.
An in-the-wild Windows Desktop Window Manager Core Library (dwmcore.dll) elevation-of-privilege vulnerability that triggers shellcode execution in dwm.exe and can be chained to SYSTEM.
An in-the-wild Windows Desktop Window Manager (DWM Core Library) elevation-of-privilege vulnerability. Exploitation executes shellcode in dwm.exe as the high-integrity Window Manager\DWM user and can subsequently elevate to SYSTEM by causing LogonUI.exe to load an attacker-dropped DLL.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.