
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20832 is a Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege vulnerability caused by a double free memory corruption flaw. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2016, 2019, 2022, and 2025. It carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-415 (Double Free), meaning the RPC IDL component incorrectly frees the same memory region twice, potentially allowing an attacker to corrupt heap memory and redirect code execution. Exploitation requires only low-privileged local access and no user interaction, making it straightforward for an authenticated local attacker to trigger the flaw. The attack vector is local (AV:L), with low attack complexity (AC:L) and no user interaction required (UI:N), indicating the vulnerability can be reliably triggered by a low-privileged user on an affected system (Microsoft MSRC, Feedly).
Successful exploitation allows a low-privileged local attacker to escalate privileges to SYSTEM level, achieving full control over the affected machine. This grants the ability to install malware, steal sensitive data, modify system configurations, disable security controls, and potentially pivot to other systems on the network. All three security pillars — confidentiality, integrity, and availability — are rated HIGH impact, reflecting the severity of a full system compromise (Feedly).
Microsoft released patches on January 13, 2026 as part of the January 2026 Patch Tuesday. Administrators should apply the following minimum build versions: Windows Server 2016 / Windows 10 1607 (10.0.14393.8783+), Windows 10 1809 / Windows Server 2019 (10.0.17763.8276+), Windows 10 21H2 (10.0.19044.6809+), Windows 10 22H2 (10.0.19045.6809+), Windows Server 2022 (10.0.20348.4648+), Windows Server 2022 23H2 (10.0.25398.2092+), Windows 11 23H2 (10.0.22631.6491+), Windows 11 24H2 (10.0.26100.7623+), Windows 11 25H2 (10.0.26200.7623+), and Windows Server 2025 (10.0.26100.32230+). As a defense-in-depth measure, limit local user access to sensitive systems and enforce the principle of least privilege to reduce the attack surface (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader January 2026 Patch Tuesday roundups by multiple security outlets. Zero Day Initiative noted it in their monthly security update review, and BleepingComputer reported on the full January 2026 Patch Tuesday release fixing 114 flaws including 3 zero-days. Rapid7 and Sophos also included it in their Patch Tuesday analyses. No specific researcher commentary or notable social media discussion focused exclusively on this CVE has been identified (ZDI Blog, BleepingComputer, Rapid7).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."