
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20824 is a protection mechanism failure in Windows Remote Assistance that allows an unauthorized local attacker to bypass a security feature. Specifically, the vulnerability enables bypassing of Mark of the Web (MotW) protections, allowing files downloaded from the internet to be treated as trusted. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium), assigned by Microsoft (MSRC Advisory, Feedly). Affected products span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2012/2012 R2, 2016, 2019, 2022, 2022 23H2, and Windows Server 2025.
The vulnerability is classified under CWE-693 (Protection Mechanism Failure), indicating that Windows Remote Assistance fails to properly enforce a security control — specifically the Mark of the Web (MotW) mechanism that flags files originating from the internet (MSRC Advisory, eSecurity Planet). The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction (UI:R), suggesting the exploitation path involves a user opening or interacting with a crafted file or Remote Assistance session that strips or bypasses MotW zone identifiers. By bypassing MotW, an attacker can cause the operating system to treat potentially malicious files as locally trusted, circumventing downstream security controls such as SmartScreen and Protected View in Office applications (Purple Ops, GBHackers).
Successful exploitation results in a high confidentiality impact — an attacker can access sensitive information that would otherwise be protected by the MotW security boundary, with no integrity or availability impact (MSRC Advisory). By bypassing MotW, an attacker could cause the system to execute or open files from untrusted internet sources without triggering standard security warnings, potentially enabling follow-on attacks such as malware execution or credential theft. The vulnerability affects a broad scope of Windows client and server platforms, increasing the potential attack surface across enterprise environments (Feedly).
Zone.Identifier alternate data stream (ADS) despite originating from an external/internet source; unexpected executables or scripts in user temp or download directories without MotW markings.msra.exe (Windows Remote Assistance executable); execution of files from temp directories without SmartScreen prompts being logged.Microsoft-Windows-RemoteAssistance/Operational); absence of expected SmartScreen or MotW-related audit events for files opened after a Remote Assistance session.Microsoft released patches for all affected Windows versions as part of the January 13, 2026 Patch Tuesday update. Fixed build versions include: Windows 10 1607 (10.0.14393.8783), Windows 10 1809 (10.0.17763.8276), Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 11 23H2 (10.0.22631.6491), Windows 11 24H2 (10.0.26100.7623), Windows 11 25H2 (10.0.26200.7623), Windows Server 2012 (6.2.9200.25868), Windows Server 2012 R2 (6.3.9600.22968), Windows Server 2016 (10.0.14393.8783), Windows Server 2019 (10.0.17763.8276), Windows Server 2022 (10.0.20348.4648), Windows Server 2022 23H2 (10.0.25398.2092), and Windows Server 2025 (10.0.26100.32230) (MSRC Advisory). As a workaround where patching is not immediately possible, administrators should restrict or disable Windows Remote Assistance via Group Policy, limit local user access to sensitive systems, and educate users to avoid accepting unsolicited Remote Assistance sessions (Feedly Executive Summary).
The vulnerability received coverage as part of broader January 2026 Patch Tuesday reporting, with security outlets such as BleepingComputer, CyberSecurityNews, and GBHackers noting it among the 114 flaws patched that month (BleepingComputer, CyberSecurityNews). Dedicated follow-up articles specifically highlighted the MotW bypass nature of the flaw, with eSecurity Planet and GBHackers publishing focused analyses (eSecurity Planet, GBHackers). The Zero Day Initiative's January 2026 security update review also covered the vulnerability as part of the broader patch batch (ZDI Blog). Community discussion noted that the January 2026 update caused some unrelated issues with Citrix Director and Windows 11 stability, though these were separate from the CVE itself.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."