
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20820 is a heap-based buffer overflow vulnerability in the Windows Common Log File System (CLFS) Driver that allows a locally authenticated attacker to elevate privileges. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607 through 22H2), Windows 11 (23H2 through 25H2), Windows Server 2008 SP2 through Windows Server 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) in the Windows Common Log File System (CLFS) kernel driver (clfs.sys). An attacker with low-privileged local access can trigger the overflow by supplying malformed input to the CLFS driver, corrupting heap memory in a way that enables privilege escalation to SYSTEM level. Exploitation requires no user interaction and has low attack complexity, making it straightforward for any authenticated local user to attempt. A root cause analysis has been published by security researchers at inbits-sec (inbits-sec Root Cause, Microsoft MSRC).
Successful exploitation allows a low-privileged local attacker to escalate to SYSTEM-level privileges, resulting in complete compromise of confidentiality, integrity, and availability on the affected host. An attacker gaining SYSTEM access can install malware, steal sensitive credentials and data, modify system configurations, disable security controls, and use the compromised host as a pivot point for lateral movement within the network. The vulnerability affects a wide range of Windows systems spanning from Windows Server 2008 R2 through Windows Server 2025 and Windows 10/11 across multiple versions (Feedly, Microsoft MSRC).
clfs.sys) is present and active.SYSTEM context that were previously executing as low-privileged users; unusual child processes spawned from user-mode applications with SYSTEM-level tokens.MEMORY.DMP) or minidumps referencing clfs.sys in the call stack.clfs.sys or related CLFS log files (.blf, .jrs) in unusual directories; new files or scheduled tasks created by SYSTEM-level processes following low-privileged user activity.Microsoft released security updates on January 13, 2026 addressing CVE-2026-20820 across all affected Windows versions. Administrators should apply the following patches immediately: Windows Server 2008 SP2 to build 6.0.6003.23717, Windows Server 2008 R2 SP1 to 6.1.7601.28117, Windows Server 2012/R2 to 6.2.9200.25868/6.3.9600.22968, Windows Server 2016 and Windows 10 1607 to 10.0.14393.8783, Windows 10 1809/Server 2019 to 10.0.17763.8276, Windows 10 21H2/22H2 to 10.0.19044.6809/10.0.19045.6809, Windows 11 23H2 to 10.0.22631.6491, Windows Server 2022 to 10.0.20348.4648, Windows Server 2022 23H2 to 10.0.25398.2092, Windows 11 24H2/Server 2025 to 10.0.26100.7623/10.0.26100.32230, and Windows 11 25H2 to 10.0.26200.7623. No official workaround is available; patching is the only remediation (Microsoft MSRC).
The vulnerability was covered as part of broader January 2026 Patch Tuesday reporting, with security outlets noting the wide scope of affected Windows versions. Cisco Talos, Zero Day Initiative, Qualys, and BleepingComputer all included it in their Patch Tuesday roundups, highlighting the CLFS driver as a recurring target for privilege escalation exploits (Talos Blog, ZDI Blog, Qualys Blog, BleepingComputer). The blue team security community on Reddit and Bluesky discussed the vulnerability in the context of CLFS forensics and detection, with a notable thread titled "Chasing the Ghost in the Log" examining deep-dive detection approaches (Reddit BlueteamSec). Flare Intelligence published post-patch analysis tracking cybercrime activity following the January 2026 Patch Tuesday release (Flare Intelligence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."