logo

Patch diff to SYSTEM

ID: 343d591d-169f-5a0d-80c6-49f0e2661e83

STIX ID: report--343d591d-169f-5a0d-80c6-49f0e2661e83

Feed Name: Elastic Security Labs

Threat Score
85/100

Date Published: 2026-03-06

Date Updated: 2026-08-27

Author: Joe Desimone

...
...

This report details a Use-After-Free vulnerability in dwmcore.dll (CSynchronousSuperWetInk destructor) discovered in the January 2026 patch set, shows the patch that unconditionally calls RemoveSource, and documents a complete exploit chain that allows a low-privilege DirectComposition application to trigger a UAF, reclaim the freed allocation with a RECT-buffer spray (GetRECT), bypass CFG using a KCT/__fnINSTRING dispatch and CStdAsyncStubBuffer2_Disconnect gadget chain to mark the spray RWX and execute inline shellcode, ultimately achieving SYSTEM-level execution; the author also highlights how large language models accelerated exploit development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.