# CVE-2026-61923 — Windows Display Enhancement Service Under-Validated Sensor Device-Id in the RPC Handlers → Heap Buffer Overflow

---

## Summary

| | |
|---|---|
| **Product** | Windows — `microsoft.graphics.display.displayenhancementservice.dll` (Display Enhancement Service, runs as SYSTEM) |
| **CVE ID** | CVE-2026-61923 |
| **Impact** | Elevation of Privilege (to SYSTEM) |
| **MSRC severity** | Important |
| **CVSS** | 7.8 / 6.8 — `CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` |
| **CWE** | CWE-122: Heap-based Buffer Overflow |
| **Delivery** | Local — a crafted sensor device-id over the service's RPC interface |
| **KB / Fixed build** | KB5121003 — DisplayEnhancementService 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `...displayenhancementservice.dll` 10.0.26100.8972 — SHA256 `66735046a32d9224b49a876b3e4d11dd69615f548904c1431e2f855a657031a0` |
| **Post-patch binary** | `...displayenhancementservice.dll` 10.0.26100.9168 — SHA256 `3a2f7bbedeeaecb57846fc3351e16f423a43f8364899fd98d07d517de9192ed6` |
| **Feature flag** | `Feature_702787896` — **the fix is CFR-gated** |
| **Exploitability** | Exploitation Less Likely; not publicly disclosed; not exploited (per MSRC) |

---

## Product Description

The Windows **Display Enhancement Service** exposes RPC methods that configure the
light sensors used for adaptive display features. Several accept a **sensor device-id
string** from the caller:
`DeManagementRpcServerSetAmbientLightSensorDeviceId`,
`DeManagementRpcServerSetColorLightSensorDeviceId`, and
`DeManagementRpcServerOpenFromMonitorId`.

---

## Vulnerability Summary

Pre-patch, these handlers only **null-checked** the client-supplied device-id string
and then used it (building a `std::wstring` / copying it) **without validating its
length**. A caller could therefore pass an over-long device-id string, overflowing
the heap buffer that receives it (CWE-122). Because the service runs as **SYSTEM** and
the RPC interface is reachable by a local user, the overflow is a local
elevation-of-privilege primitive to SYSTEM (per the MSRC FAQ).

---

## Prerequisites and Constraints

- Local, low-privileged (`PR:L`, `AV:L`, `AC:L`): call the Display Enhancement Service
  sensor-device-id RPC methods.
- Supply a device-id string longer than the expected bound (≥ `0x401` WCHARs).
- Result: the over-long id overflows the service's heap buffer.

---

## Vulnerability Details

### Root Cause

The RPC handlers used the caller-supplied device-id string after only a null check,
with no length validation, so an over-long id overflowed the receiving heap buffer.

### The patch (confirmed — diff, .8972 → .9168)

Gated behind `Feature_702787896`, the handlers now call a **new validator
`IsValidSensorDeviceId`** on the device-id before using it. The validator bounds the
string length below `0x401` (1025) WCHARs:

```c
// IsValidSensorDeviceId (10.0.26100.9168) — NEW (from the diff)
bool IsValidSensorDeviceId(ushort *id) {
    if (id == NULL) return false;
    return wcsnlen((wchar_t*)id, 0x401) < 0x401;     // *** length bound ***
}

// DeManagementRpcServerSet{Ambient,Color}LightSensorDeviceId (.9168) — PATCHED
// pre : if (param_2 != NULL) { ... use id ... }
// post:
if ((!Feature_702787896__private_IsEnabled()) || IsValidSensorDeviceId(param_2)) {
    // build wstring / use the id  -- only for a length-validated id
} // else reject
```

With the device-id required to be non-null and shorter than `0x401` WCHARs before
use, an over-long id is rejected, closing the heap overflow.

### Patch Completeness Assessment

**CFR-gated behind `Feature_702787896`.** The length validation runs only when the
flag is enabled; the original unchecked path still ships when disabled. Verify
`Feature_702787896` is enabled to confirm the fix is live.

---

## Detection Guidance

**Behavioural.** Display Enhancement Service sensor-device-id RPC calls carrying
unusually long device-id strings (≥ 1025 chars); heap-overflow / pool-corruption
bugchecks in
`displayenhancementservice!DeManagementRpcServerSet*LightSensorDeviceId` on
unpatched/flag-disabled builds.

**Config.** The fix is CFR-gated — confirm `Feature_702787896` is enabled.

---

## References

- MSRC advisory — CVE-2026-61923 (Windows Display Enhancement Service Elevation of Privilege), released 2026-08-11, KB5121003.
- Full binary diff: `/data/patch_diffs/displayenhancementservice_dll-cve-2026-61923-ghidriff.md`
