ZeroHour

CVE-2026-20805

KEV PoC mass1

Local Information Disclosure in Microsoft Desktop Windows Manager (CVE-2026-20805)

CISA: Microsoft Windows Information Disclosure Vulnerability

CVSS 3.1
5.5 medium
EPSS
5%p92
Published
()
KEV added
AI analysis

CVE-2026-20805 is an information disclosure flaw (CWE-200) in Desktop Windows Manager (DWM) that exposes sensitive information to an unauthorized actor. An authorized attacker with local access and low privileges can trigger the flaw without user interaction and read sensitive data to which they should not have access. All supported Windows client versions from Windows 10 1607 through Windows 11 25H2 and Windows Server from 2012 through 2022 23H2 are affected, meaning essentially the entire installed Windows estate. The flaw was fixed in Microsoft's January 2026 Patch Tuesday release and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-13, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is available.

What to do: Deploy the January 2026 Microsoft security updates (Patch Tuesday) for every affected Windows 10/11 client and Windows Server release, prioritizing internet-facing and multi-user systems. Federal agencies must apply the updates per BOD 22-01 timelines following the KEV listing on 2026-01-13; other organizations should treat this as a priority patch given confirmed in-the-wild exploitation. After patching, review local account activity on Windows endpoints for signs of low-privileged information gathering, and note that patching is the primary mitigation since the flaw requires only local access.

Affected
microsoft Windows 101607
microsoft Windows 101809
microsoft Windows 1021H2
microsoft Windows 1022H2
microsoft Windows 1123H2
microsoft Windows 1124H2
microsoft Windows 1125H2
microsoft Windows Server2012
microsoft Windows Server2016
microsoft Windows Server2019
microsoft Windows Server2022
microsoft Windows Server2022 23H2
Estimated exposure
masshundreds of millions of Windows client devices plus millions of Windows Server instances across all listed versions — Every supported Windows 10/11 client release and Windows Server release from 2012 to 2022 23H2 is in scope, so the exposed population is effectively Microsoft's full install base (well over a billion client devices and tens of millions of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-200
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news