
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20840 is a heap-based buffer overflow vulnerability in Windows NTFS that allows a locally authenticated, low-privileged attacker to execute arbitrary code without user interaction. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects a broad range of Windows versions spanning from Windows Server 2008 SP2 through Windows 11 25H2 and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (Microsoft MSRC, Feedly).
The root cause is a heap-based buffer overflow (CWE-122) in the Windows NT File System (NTFS) driver. An attacker with low-privileged local access can trigger the overflow — likely by crafting a malicious NTFS volume or file structure that causes the driver to write beyond the bounds of an allocated heap buffer — without requiring any user interaction. The attack vector is local (AV:L), with low attack complexity and low privilege requirements, making it straightforward to exploit once local access is obtained (Microsoft MSRC, Feedly). No public technical write-up or proof-of-concept code has been identified at this time.
Successful exploitation grants an attacker the ability to execute arbitrary code in the context of the NTFS driver, which operates at the kernel level, potentially leading to complete system compromise. All three security pillars are affected: high confidentiality impact (access to sensitive data), high integrity impact (modification of system files and data), and high availability impact (system disruption or crash). Given the kernel-level nature of NTFS exploitation, a successful attack could facilitate privilege escalation to SYSTEM, enabling lateral movement within a network or persistent access (Feedly).
Microsoft released patches on January 13, 2026, addressing this vulnerability across all affected Windows versions. Key patched build numbers include: Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 10 1607/Server 2016 (10.0.14393.8783), Windows 10 1809/Server 2019 (10.0.17763.8276), Windows 11 23H2 (10.0.22631.6491), Windows 11 24H2 (10.0.26100.7623), Windows 11 25H2 (10.0.26200.7623), Windows Server 2022 (10.0.20348.4648), Windows Server 2022 23H2 (10.0.25398.2092), and Windows Server 2025 (10.0.26100.32230). Organizations should apply the January 2026 cumulative updates immediately, prioritize systems with local user access exposure, and enforce the principle of least privilege to reduce the attack surface (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader January 2026 Patch Tuesday roundups by multiple security vendors and researchers. Tenable noted it among the 113 CVEs addressed that month, and Cisco Talos, Zero Day Initiative, Qualys, and Sophos all published Patch Tuesday reviews that included this flaw (Tenable Blog, ZDI Blog, Qualys Blog, Sophos Blog). BleepingComputer and CSO Online also reported on the January 2026 Patch Tuesday, noting the broader context of three zero-days patched in the same release (BleepingComputer). No specific controversy or notable social media discussion was identified for this individual CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."