
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20851 is an out-of-bounds read vulnerability in the Windows Capability Access Management Service (camsvc) that allows an unauthorized local attacker to disclose sensitive information. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday security update cycle. Affected products include Windows 11 version 24H2 (before build 10.0.26100.7623), Windows 11 version 25H2 (before build 10.0.26200.7623), and Windows Server 2025 (before build 10.0.26100.32230). The vulnerability carries a CVSS v3.1 base score of 6.2 (Medium), assigned by Microsoft (Microsoft MSRC, Feedly).
The root cause is classified as CWE-125 (Out-of-bounds Read), where the Capability Access Management Service (camsvc) fails to properly validate memory boundaries when processing certain inputs, allowing memory contents beyond the intended buffer to be read. The attack vector is local, requiring no privileges and no user interaction, with low attack complexity — meaning any local process or user on the system could potentially trigger the read. The vulnerability is scoped to confidentiality impact only, with no integrity or availability consequences. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation allows a local attacker to read memory contents from the Capability Access Management Service process, potentially exposing sensitive data such as credentials, authentication tokens, or other confidential information held in memory. The impact is limited to information disclosure — there is no direct path to code execution, data modification, or denial of service through this vulnerability alone. However, disclosed credentials or tokens could facilitate lateral movement or privilege escalation as a secondary step (Feedly).
As of the time of disclosure, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.039%, indicating a very low probability of exploitation in the near term. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported in connection with this CVE.
Microsoft released patches on January 13, 2026, addressing this vulnerability. Organizations should update to the following minimum builds: Windows 11 24H2 → build 10.0.26100.7623 or later; Windows 11 25H2 → build 10.0.26200.7623 or later; Windows Server 2025 → build 10.0.26100.32230 or later. As a complementary measure, restrict local access to sensitive systems, enforce the principle of least privilege for user accounts, and monitor for suspicious memory access patterns. No configuration-based workaround has been published by Microsoft (Microsoft MSRC, Feedly).
CVE-2026-20851 was covered as part of broader January 2026 Patch Tuesday roundups by several security outlets including BleepingComputer, Cybersecurity News, Zero Day Initiative, SANS ISC, and Sophos, though it did not receive individual spotlight coverage given its medium severity rating. Community discussion was minimal, with most attention directed toward the three zero-days patched in the same update cycle (BleepingComputer, ZDI, SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."