📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Government/Critical Infrastructure CRITICAL 1h Global vulnerability Enterprise Software / Data Analytics CRITICAL 2h Global vulnerability Artificial Intelligence and Technology HIGH 5h Global general Technology and Artificial Intelligence MEDIUM 9h Global general Technology and Artificial Intelligence HIGH 10h Global vulnerability Higher Education CRITICAL 19h Global data_breach Government HIGH 20h Global supply_chain Software Development and Open Source Communities CRITICAL 20h Global malware Software Development CRITICAL 20h Global phishing Multiple Sectors HIGH 20h Global apt Government/Critical Infrastructure CRITICAL 1h Global vulnerability Enterprise Software / Data Analytics CRITICAL 2h Global vulnerability Artificial Intelligence and Technology HIGH 5h Global general Technology and Artificial Intelligence MEDIUM 9h Global general Technology and Artificial Intelligence HIGH 10h Global vulnerability Higher Education CRITICAL 19h Global data_breach Government HIGH 20h Global supply_chain Software Development and Open Source Communities CRITICAL 20h Global malware Software Development CRITICAL 20h Global phishing Multiple Sectors HIGH 20h Global apt Government/Critical Infrastructure CRITICAL 1h Global vulnerability Enterprise Software / Data Analytics CRITICAL 2h Global vulnerability Artificial Intelligence and Technology HIGH 5h Global general Technology and Artificial Intelligence MEDIUM 9h Global general Technology and Artificial Intelligence HIGH 10h Global vulnerability Higher Education CRITICAL 19h Global data_breach Government HIGH 20h Global supply_chain Software Development and Open Source Communities CRITICAL 20h Global malware Software Development CRITICAL 20h Global phishing Multiple Sectors HIGH 20h
Vulnerabilities

CVE-2026-25189

High
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CWE-416 — Weakness Type
Published: Mar 10, 2026  ·  Modified: Mar 17, 2026  ·  Source: NVD
CVSS v3
7.8
🔗 NVD Official
📄 Description (English)

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

🤖 AI Executive Summary

CVE-2026-25189 is a use-after-free vulnerability in Windows DWM Core Library affecting Windows 10 and Server 2019/2022, allowing authorized local attackers to escalate privileges with a CVSS score of 7.8. While no public exploit is currently available, the vulnerability requires local access and valid credentials, making it a significant risk for multi-user systems and shared infrastructure. Immediate patching is critical for Saudi organizations managing Windows-based infrastructure, particularly in government and banking sectors where privilege escalation could lead to unauthorized access to sensitive systems.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 29, 2026 07:03
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi banking sector (SAMA-regulated institutions), government agencies (NCA oversight), and critical infrastructure operators. Windows Server 2019/2022 deployments in data centers supporting ARAMCO, STC, and other critical sectors are particularly vulnerable. The privilege escalation capability could enable lateral movement within enterprise networks, compromising sensitive financial data, government records, and operational technology systems. Organizations with shared workstations or terminal server environments face elevated risk of insider threats and unauthorized system access.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Energy and Utilities Telecommunications Healthcare Critical Infrastructure Defense and Security
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Windows 10 (versions 1809, 21H2, 22H2) and Windows Server 2019/2022 systems in your environment
2. Prioritize patching for systems with multiple user accounts or remote access capabilities
3. Implement access controls restricting local logon to authorized personnel only
4. Monitor for suspicious privilege escalation attempts in Windows Event Viewer (Event ID 4688, 4689)

PATCHING GUIDANCE:
1. Apply latest Windows security updates from Microsoft immediately upon availability
2. Test patches in non-production environment before enterprise deployment
3. Schedule patching during maintenance windows to minimize business disruption
4. Verify patch installation using 'Get-HotFix' PowerShell command

COMPENSATING CONTROLS (if patch unavailable):
1. Restrict local interactive logon privileges using Group Policy (Deny log on locally)
2. Disable unnecessary services and disable DWM if not required for business operations
3. Implement application whitelisting to prevent unauthorized privilege escalation tools
4. Enable Windows Defender Application Guard for isolated execution environments

DETECTION RULES:
1. Monitor Windows Event Log for Event ID 4672 (Special privileges assigned to new logon)
2. Alert on unexpected process creation with elevated privileges from DWM-related processes
3. Track modifications to HKLM\System\CurrentControlSet\Services registry keys
4. Monitor for abnormal DWM.exe behavior using EDR/XDR solutions
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع أنظمة Windows 10 (الإصدارات 1809 و 21H2 و 22H2) و Windows Server 2019/2022 في بيئتك
2. إعطاء الأولوية لتصحيح الأنظمة التي تحتوي على حسابات مستخدمين متعددة أو إمكانيات الوصول عن بعد
3. تنفيذ عناصر التحكم في الوصول التي تقيد تسجيل الدخول المحلي للموظفين المصرحين فقط
4. مراقبة محاولات تصعيد الامتيازات المريبة في Windows Event Viewer (معرف الحدث 4688 و 4689)

إرشادات التصحيح:
1. تطبيق أحدث تحديثات أمان Windows من Microsoft فور توفرها
2. اختبار التصحيحات في بيئة غير الإنتاج قبل نشر المؤسسة
3. جدولة التصحيح أثناء نوافذ الصيانة لتقليل انقطاع الأعمال
4. التحقق من تثبيت التصحيح باستخدام أمر PowerShell 'Get-HotFix'

عناصر التحكم البديلة (إذا لم يكن التصحيح متاحًا):
1. تقييد امتيازات تسجيل الدخول التفاعلي المحلي باستخدام Group Policy
2. تعطيل الخدمات غير الضرورية وتعطيل DWM إذا لم تكن مطلوبة لعمليات الأعمال
3. تنفيذ القائمة البيضاء للتطبيقات لمنع أدوات تصعيد الامتيازات غير المصرح بها
4. تفعيل Windows Defender Application Guard للبيئات المنفصلة

قواعد الكشف:
1. مراقبة سجل أحداث Windows لمعرف الحدث 4672 (امتيازات خاصة مخصصة لتسجيل دخول جديد)
2. التنبيه على إنشاء عملية غير متوقعة بامتيازات مرتفعة من العمليات المتعلقة بـ DWM
3. تتبع التعديلات على مفاتيح سجل HKLM\System\CurrentControlSet\Services
4. مراقبة سلوك DWM.exe غير الطبيعي باستخدام حلول EDR/XDR
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information security policies and procedures A.5.2.1 - User registration and de-registration A.5.2.2 - User access provisioning A.5.2.3 - Management of privileged access rights A.5.2.4 - Review of user access rights A.8.1.1 - User endpoint devices A.8.2.1 - Privileged access rights A.8.2.2 - Restriction of access to information A.8.2.3 - Password management A.8.3.1 - Encryption and key management
🔵 SAMA CSF
Governance & Risk Management - System and Information Integrity Protective Security - Access Control and Authentication Protective Security - Vulnerability Management Protective Security - Patch Management Operational Resilience - Incident Response
🟡 ISO 27001:2022
A.5.1.1 - Policies for information security A.5.2.1 - Information security responsibilities A.5.2.2 - Information security in supplier relationships A.6.1.1 - Screening A.6.2.1 - Prior to employment A.8.1.1 - User endpoint devices A.8.2.1 - Privileged access rights A.8.2.2 - Restriction of access to information A.8.3.1 - Encryption and key management A.8.3.2 - Cryptography A.8.3.3 - Separation of duties
🟣 PCI DSS v4.0.1
Requirement 2.1 - Default security parameters Requirement 6.2 - Security patches and updates Requirement 7.1 - Limit access to system components Requirement 7.2 - Establish access for users Requirement 8.1 - Assign unique ID to each user Requirement 8.2 - Ensure proper user authentication
📦 Affected Products / CPE 10 entries
microsoft:windows_10_1809
microsoft:windows_10_1809
microsoft:windows_10_21h2
microsoft:windows_10_21h2
microsoft:windows_10_21h2
microsoft:windows_10_22h2
microsoft:windows_10_22h2
microsoft:windows_10_22h2
microsoft:windows_server_2019
microsoft:windows_server_2022
📊 CVSS Score
7.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.8
CWECWE-416
Exploit No
Patch ✓ Yes
Published 2026-03-10
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-416
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.