Patch diff to SYSTEM
ID: 343d591d-169f-5a0d-80c6-49f0e2661e83
STIX ID: report--343d591d-169f-5a0d-80c6-49f0e2661e83
Feed Name: Elastic Security Labs
This report details a Use-After-Free vulnerability in dwmcore.dll (CSynchronousSuperWetInk destructor) discovered in the January 2026 patch set, shows the patch that unconditionally calls RemoveSource, and documents a complete exploit chain that allows a low-privilege DirectComposition application to trigger a UAF, reclaim the freed allocation with a RECT-buffer spray (GetRECT), bypass CFG using a KCT/__fnINSTRING dispatch and CStdAsyncStubBuffer2_Disconnect gadget chain to mark the spray RWX and execute inline shellcode, ultimately achieving SYSTEM-level execution; the author also highlights how large language models accelerated exploit development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
