CVE-2026-61923 — Windows Display Enhancement Service Elevation of Privilege Vulnerability
Executive Summary
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1809 for 32-bit Systems | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5120240 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5120240 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5120238 |
Security Update | Yes |
5120249 |
Security Update | Yes |
5120240 |
Security Update | Yes |
5121000 |
Security Update | Yes |
Patch Diff
Heap-based buffer overflow (CWE-122) in the Windows Display Enhancement Service (microsoft.graphics.display.displayenhancementservice.dll) sensor-device-id RPC handlers, local EoP to SYSTEM. The service exposes RPC methods that accept a sensor device-id string from the client - DeManagementRpcServerSetAmbientLightSensorDeviceId, DeManagementRpcServerSetColorLightSensorDeviceId (and OpenFromMonitorId). PRE: the handlers only null-checked the client-supplied device-id string (param_2) and then used it (building a std::wstring / copying it) without validating its length, so an over-long device id overflowed the heap buffer. Because the service runs as SYSTEM and the RPC interface is reachable by a local user, the overflow is a local EoP-to-SYSTEM primitive. Diff of the service DLL 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flag Feature_702787896, the handlers now call a new validator IsValidSensorDeviceId(param_2) before using the id - IsValidSensorDeviceId returns true only when the string is non-null and wcsnlen(id, 0x401) < 0x401 (i.e. length bounded below 1025 WCHARs) - so an over-long device id is rejected (if (!feature || IsValidSensorDeviceId(param_2)) { ...use... }), closing the heap overflow.
| Function | Address | Change | Note |
|---|---|---|---|
IsValidSensorDeviceId |
new function |
added (length validator) | New: bool IsValidSensorDeviceId(ushort *id) returns id != NULL && wcsnlen(id, 0x401) < 0x401 - bounds the device-id string length below 1025 WCHARs. |
DeManagementRpcServerSetAmbientLightSensorDeviceId |
code change |
code (device-id validated before use, CFR-gated) | Pre: only if (param_2 != NULL) then use the id. Post (Feature_702787896): if ((!feature) || IsValidSensorDeviceId(param_2)) before building the wstring / using it; over-long id rejected. |
DeManagementRpcServerSetColorLightSensorDeviceId |
code change |
code (device-id validated before use, CFR-gated) | Same IsValidSensorDeviceId(param_2) length gate added under Feature_702787896. |
DeManagementRpcServerOpenFromMonitorId |
code change |
code (monitor-id path updated) | Related RPC handler updated alongside under the same gate. |
Feature_702787896 |
gate |
added (CFR gate) | CFR flag gating the IsValidSensorDeviceId length validation; the original unchecked path still ships when disabled. |
Attack Path
An over-long sensor device-id sent to the Display Enhancement Service RPC overflows a heap buffer
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
Detection Rules
Acknowledgments
Anonymous