CVE-2026-21519

HIGH KEV

Microsoft Windows 10 1607 < 10.0.14393.8868 - Type Confusion

Title source: rule

Description

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Scores

CVSS v3 7.8
EPSS 0.0452
EPSS Percentile 89.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2026-02-10
VulnCheck KEV 2026-02-10
ENISA EUVD EUVD-2026-7358
CWE
CWE-843
Status published
Products (30)
microsoft/windows_10_1607 < 10.0.14393.8868 (2 CPE variants)
microsoft/windows_10_1809 < 10.0.17763.8389 (2 CPE variants)
microsoft/windows_10_21h2 < 10.0.19044.6937 (3 CPE variants)
microsoft/windows_10_22h2 < 10.0.19045.6937 (3 CPE variants)
Microsoft/Windows 10 Version 1607 10.0.14393.0 - 10.0.14393.8868
Microsoft/Windows 10 Version 1809 10.0.17763.0 - 10.0.17763.8389
Microsoft/Windows 10 Version 21H2 10.0.19044.0 - 10.0.19044.6937
Microsoft/Windows 10 Version 22H2 10.0.19045.0 - 10.0.19045.6937
microsoft/windows_11_23h2 < 10.0.22631.6649 (2 CPE variants)
microsoft/windows_11_24h2 < 10.0.26100.7781 (2 CPE variants)
... and 20 more
Published Feb 10, 2026
KEV Added Feb 10, 2026
Tracked Since Feb 18, 2026