CVE-2026-20805

9.5 CISA KEV

Microsoft · Windows

A local information disclosure vulnerability in the Desktop Windows Manager allows an authenticated attacker to access sensitive information.

Executive summary

This vulnerability is actively exploited in the wild and allows an authenticated local attacker to bypass security measures by exposing sensitive information within the Windows Desktop Window Manager.

Vulnerability

The flaw exists within the Desktop Windows Manager (DWM) component and arises from improper handling of sensitive information. An authenticated local attacker can leverage this weakness to view data that should be restricted, potentially facilitating subsequent privilege escalation or system compromise.

Business impact

Successful exploitation allows an attacker to gain unauthorized access to sensitive information stored within the system memory or DWM processes. Given the CVSS score of 9.5 and its confirmed status in the CISA Known Exploited Vulnerabilities catalog, this vulnerability poses a severe risk to data confidentiality and organizational integrity. Failure to remediate this flaw may allow attackers to bypass critical security boundaries and gain deeper access to the network.

Remediation

Immediate Action: Apply the January 2026 security updates provided by Microsoft to all affected Windows systems immediately.

Proactive Monitoring: Monitor system logs for unauthorized access attempts or unusual process behavior involving the Desktop Window Manager.

Compensating Controls: Since this is a local vulnerability, ensure that endpoint protection platforms are fully updated and that user privileges are strictly managed to minimize the local attack surface.

Exploitation status

Public Exploit Available: Yes, multiple public proofs of concept are available via GitHub repositories.

Analyst recommendation

Due to the critical nature of this vulnerability and the confirmed reports of active exploitation in the wild, organizations must prioritize the deployment of the January 2026 security patches. Administrators should verify successful installation of the relevant updates across all enterprise endpoints to mitigate the risk of data exposure and potential secondary exploitation.

More Microsoft CVEs

Sources