Important CVSS 7.8 EPSS 0.00311 🔬 Patch diffed 2026-08 archive

Executive Summary

Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

Overview

7.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released Aug 11 2026
Last Updated Aug 11 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00311 — 0.2368 percentile
NVD CVSS 7.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.8

EPSS Score

0.00311
probability of exploitation in the next 30 days
0.2368 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

14 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1809 for 32-bit Systems 5120238 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5120238 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for ARM64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for x64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 26H1 for x64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5120238 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5120238 (Security Update) Important Elevation of Privilege Yes

Patches

4 patches
Article Type Restart
5120238 Security Update Yes
5120249 Security Update Yes
5120240 Security Update Yes
5121000 Security Update Yes

Patch Diff

ghidriff · microsoft.graphics.display.displayenhancementservice.dll (KB5121003)

Heap-based buffer overflow (CWE-122) in the Windows Display Enhancement Service (microsoft.graphics.display.displayenhancementservice.dll) sensor-device-id RPC handlers, local EoP to SYSTEM. The service exposes RPC methods that accept a sensor device-id string from the client - DeManagementRpcServerSetAmbientLightSensorDeviceId, DeManagementRpcServerSetColorLightSensorDeviceId (and OpenFromMonitorId). PRE: the handlers only null-checked the client-supplied device-id string (param_2) and then used it (building a std::wstring / copying it) without validating its length, so an over-long device id overflowed the heap buffer. Because the service runs as SYSTEM and the RPC interface is reachable by a local user, the overflow is a local EoP-to-SYSTEM primitive. Diff of the service DLL 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flag Feature_702787896, the handlers now call a new validator IsValidSensorDeviceId(param_2) before using the id - IsValidSensorDeviceId returns true only when the string is non-null and wcsnlen(id, 0x401) < 0x401 (i.e. length bounded below 1025 WCHARs) - so an over-long device id is rejected (if (!feature || IsValidSensorDeviceId(param_2)) { ...use... }), closing the heap overflow.

Pre-patch version 10.0.26100.8972 Download
Post-patch version 10.0.26100.9168 Download
Function Address Change Note
IsValidSensorDeviceId new function added (length validator) New: bool IsValidSensorDeviceId(ushort *id) returns id != NULL && wcsnlen(id, 0x401) < 0x401 - bounds the device-id string length below 1025 WCHARs.
DeManagementRpcServerSetAmbientLightSensorDeviceId code change code (device-id validated before use, CFR-gated) Pre: only if (param_2 != NULL) then use the id. Post (Feature_702787896): if ((!feature) || IsValidSensorDeviceId(param_2)) before building the wstring / using it; over-long id rejected.
DeManagementRpcServerSetColorLightSensorDeviceId code change code (device-id validated before use, CFR-gated) Same IsValidSensorDeviceId(param_2) length gate added under Feature_702787896.
DeManagementRpcServerOpenFromMonitorId code change code (monitor-id path updated) Related RPC handler updated alongside under the same gate.
Feature_702787896 gate added (CFR gate) CFR flag gating the IsValidSensorDeviceId length validation; the original unchecked path still ships when disabled.
View full diff report View RCA report

Attack Path

An over-long sensor device-id sent to the Display Enhancement Service RPC overflows a heap buffer

Attack path for CVE-2026-61923 An over-long sensor device-id sent to the Display Enhancement Service RPC overflows a heap buffer 01 — ENTRY Local user calls the Display Enhancement Service sensor-device-id RPC displayenhancementservice.dll (SYSTEM) DeManagementRpcServerSetAmbientLightSensorDeviceId / SetColorLightSensorDeviceId accept a device-id string. AV:L/PR:L/AC:L. 02 — CONTROLLED INPUT Supplies an over-long device-id string The client-controlled id (param_2) exceeds the expected length (>= 0x401 WCHARs). 03 — MISSING CHECK Handler uses the id without a length check (CWE-122) Pre-patch only a null check is done; the over-long id is copied/used, overflowing the heap buffer. 04 — PATH Heap buffer overflows in the SYSTEM service The over-copy corrupts adjacent heap memory. 05 — PRIMITIVE Heap overflow in the SYSTEM service -> EoP to SYSTEM The Aug 2026 fix (Feature_702787896) validates the id via IsValidSensorDeviceId (wcsnlen < 0x401) before use.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

Detection Rules

Acknowledgments

Anonymous