
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20819 is an untrusted pointer dereference vulnerability in Windows Virtualization-Based Security (VBS) Enclave that allows a locally authorized, low-privileged attacker to disclose sensitive information. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday release. Affected versions include Windows 11 23H2 (before build 10.0.22631.6491), Windows 11 24H2 (before build 10.0.26100.7623), and Windows 11 25H2 (before build 10.0.26200.7623). The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium), assigned by Microsoft (Microsoft MSRC).
The root cause is an untrusted pointer dereference (CWE-822) within the Windows VBS Enclave component, a security feature designed to isolate sensitive code and data from the rest of the operating system. An attacker who already has local access and low-level privileges can supply or influence a pointer value that the VBS Enclave component dereferences without adequate validation, leading to unauthorized memory reads. The attack vector is local, requires no user interaction, and has low attack complexity, meaning exploitation is straightforward once local access is obtained. No public proof-of-concept or technical write-up detailing the specific exploitation mechanics has been published (Microsoft MSRC, Feedly).
Successful exploitation results in high confidentiality impact — a low-privileged local attacker can read sensitive memory contents from within the VBS Enclave, potentially exposing cryptographic keys, credentials, or other protected data that the enclave is designed to safeguard. There is no integrity or availability impact. Because VBS Enclaves are specifically used to protect high-value secrets, unauthorized disclosure from this component could undermine the security guarantees of the broader Virtualization-Based Security architecture on affected Windows 11 systems (Microsoft MSRC, Feedly).
Microsoft released security updates on January 13, 2026, addressing this vulnerability across all affected Windows 11 versions. Administrators should update to the following builds or later: Windows 11 23H2 → build 10.0.22631.6491, Windows 11 24H2 → build 10.0.26100.7623, Windows 11 25H2 → build 10.0.26200.7623. Updates are available through standard Microsoft update channels (Windows Update, WSUS, Microsoft Update Catalog). No configuration-based workaround has been published; patching is the only recommended remediation (Microsoft MSRC).
CVE-2026-20819 was covered as part of broader January 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Rapid7, Sophos, and CyberSecurityNews, which collectively noted that the January 2026 update addressed 114 vulnerabilities including 3 zero-days. This specific CVE received minimal individual attention given its medium severity and local-only attack vector (BleepingComputer, Rapid7, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."