
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20853 is a local privilege escalation vulnerability in Windows WalletService caused by a race condition (improper synchronization of shared resources). Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects multiple Windows 10 and Windows 11 versions. Affected versions include Windows 10 1607 (before 10.0.14393.8783), Windows 10 1809 (before 10.0.17763.8276), Windows 10 21H2 (before 10.0.19044.6809), Windows 10 22H2 (before 10.0.19045.6809), Windows 11 23H2 (before 10.0.22631.6491), Windows 11 24H2 (before 10.0.26100.7623), and Windows 11 25H2 (before 10.0.26200.7623). It carries a CVSS v3.1 base score of 7.4 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition) within the Windows WalletService component. An attacker can exploit a time-of-check to time-of-use (TOCTOU) style race condition (CAPEC-29) by manipulating shared resources during concurrent execution to gain elevated privileges. The attack vector is local, requires no user interaction, and no prior privileges — though the high attack complexity (AC:H) indicates that precise timing or repeated attempts are needed to win the race condition. No public proof-of-concept code has been identified (Microsoft MSRC, Feedly).
Successful exploitation allows an unauthorized local attacker to elevate privileges to SYSTEM level on the affected Windows machine, resulting in high confidentiality, integrity, and availability impact. With SYSTEM-level access, an attacker can execute arbitrary code, modify critical system configurations, access sensitive data stored on the device, and potentially use the compromised host as a pivot point for lateral movement within a network. The broad scope of affected Windows versions — spanning both Windows 10 and Windows 11 across multiple release channels — significantly widens the potential attack surface (Microsoft MSRC, Feedly).
Microsoft released security updates on January 13, 2026, addressing this vulnerability across all affected Windows versions. Organizations should apply the following updates: Windows 10 1607 → 10.0.14393.8783 or later; Windows 10 1809 → 10.0.17763.8276 or later; Windows 10 21H2 → 10.0.19044.6809 or later; Windows 10 22H2 → 10.0.19045.6809 or later; Windows 11 23H2 → 10.0.22631.6491 or later; Windows 11 24H2 → 10.0.26100.7623 or later; Windows 11 25H2 → 10.0.26200.7623 or later. As a general defense-in-depth measure, restrict local user access to sensitive systems and monitor for unusual privilege escalation activity while patching is underway (Microsoft MSRC).
CVE-2026-20853 was covered as part of broader reporting on Microsoft's January 2026 Patch Tuesday, which addressed 114 vulnerabilities including 3 zero-days. Security outlets such as BleepingComputer, CyberSecurityNews, Rapid7, and Sophos covered the January 2026 Patch Tuesday release, though CVE-2026-20853 did not receive individual spotlight coverage given its high-complexity, local-only attack vector. Flare.io published post-Patch Tuesday threat intelligence tracking cybercrime activity following the January 2026 release (BleepingComputer, Rapid7, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."