logo

Patch diff to SYSTEM

ID: 95598355-6734-5936-87ee-4a3d5c404c4d

STIX ID: report--95598355-6734-5936-87ee-4a3d5c404c4d

Feed Name: Elastic Security Labs

Threat Score
80/100

Date Published: 2026-03-06

Date Updated: 2026-04-27

...
...

This write-up analyzes a Use-After-Free in CSynchronousSuperWetInk in dwmcore.dll (Windows DWM) that allows a local unprivileged process using DirectComposition to create a dangling pointer and trigger a virtual call leading to arbitrary code execution and escalation to SYSTEM; it includes the bug root cause, the Microsoft patch behavior, a full exploit which reclaims the freed allocation via a CRegionGeometry RECT spray (GetRECT), and a CFG-respecting gadget chain that makes the sprayed region executable and runs inline shellcode to spawn cmd.exe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.