
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20805 is an information disclosure vulnerability in Windows Desktop Window Manager (DWM) that allows a locally authenticated attacker with low privileges to expose sensitive memory addresses, effectively bypassing Address Space Layout Randomization (ASLR) protections. Disclosed and patched on January 13, 2026, as part of Microsoft's January Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2012 through 2025. It carries a CVSS v3.1 base score of 5.5 (Medium), though its real-world impact is significantly elevated due to active exploitation in multi-stage attack chains (Microsoft MSRC, CISA KEV).
The vulnerability is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and resides in the Desktop Window Manager, a core Windows compositing engine responsible for rendering the graphical user interface. An attacker with low-privilege local access can trigger the flaw to leak sensitive kernel memory addresses — specifically enabling them to defeat ASLR, a key exploit mitigation. This information disclosure is particularly dangerous because it serves as a prerequisite step in chained attacks: once ASLR is bypassed, attackers can reliably exploit secondary memory corruption vulnerabilities to escalate privileges or execute arbitrary code. A technical analysis published by NSHC Threat Recon and a PoC available on GitHub confirm the memory leak mechanism within DWM (NSHC Analysis, PoC GitHub).
Successful exploitation allows a low-privileged local attacker to disclose sensitive kernel memory addresses, directly undermining ASLR protections across all affected Windows versions. While the vulnerability itself does not grant code execution or privilege escalation in isolation, it is actively being chained with privilege escalation exploits in multi-stage attacks to achieve full system compromise. The broad scope of affected systems — spanning consumer Windows 10/11 and enterprise Windows Server 2012 through 2025 — means the potential attack surface is extremely wide, with implications for both endpoint and server infrastructure (Feedly Executive Summary, CISA KEV).
systeminfo, WMI queries).https://github.com/fevar54/CVE-2026-20805-POC) targeting the Desktop Window Manager process to leak kernel memory addresses via the vulnerable DWM interface.dwm.exe or unexpected memory reads targeting the DWM process from low-privileged user-space processes; anomalous access patterns to DWM handles.https://github.com/fevar54/CVE-2026-20805-POC) in user-writable directories.Microsoft released patches on January 13, 2026, as part of the January Patch Tuesday update. Administrators should apply the following patched versions immediately: Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 11 23H2 (10.0.22631.6491), Windows 11 24H2 and Server 2025 (10.0.26100.7623), Windows 11 25H2 (10.0.26200.7623), Windows Server 2016 (10.0.14393.8783), Windows Server 2019 (10.0.17763.8276), Windows Server 2022 (10.0.20348.4648), and Windows Server 2022 23H2 (10.0.25398.2092). No vendor-provided workaround exists; patching is the only remediation. Given active exploitation and CISA KEV listing, federal agencies were required to patch by February 3, 2026, and all organizations should treat this as a high-priority update (Microsoft MSRC, CISA KEV).
The vulnerability received significant attention from the security community given its zero-day status and same-day KEV listing. Cisco Talos highlighted it in their January 2026 Patch Tuesday analysis, noting its role in multi-stage attack chains (Talos). Tenable's Satnam Narang commented on the deceptive nature of its medium CVSS score relative to its real-world danger as an ASLR bypass enabler. The Record Media and Security Affairs both covered CISA's rapid KEV addition, emphasizing the urgency for federal agencies (The Record, Security Affairs). Social media discussion on X (formerly Twitter) and Mastodon was active, with Dark Reading and The Hacker News amplifying the story. India's CERT-In issued a high-risk alert for Windows users following the disclosure (Times Now).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."