
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20863 is a double free memory corruption vulnerability in the Windows Win32K ICOMP component that allows an authorized local attacker to elevate privileges. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Windows 11 versions 23H2, 24H2, and 25H2, as well as Windows Server 2022, Windows Server 2022 23H2, and Windows Server 2025. It carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-415 (Double Free), a memory safety issue in the Win32K ICOMP subsystem where a memory region is freed more than once, potentially allowing an attacker to corrupt heap memory and redirect code execution (Microsoft MSRC). Exploitation requires local access with low-level user privileges and is rated as high attack complexity, meaning the attacker must satisfy specific conditions or timing requirements to trigger the double free condition reliably. No user interaction is required once the attacker has local access. No public technical write-ups or proof-of-concept code have been identified at this time (Feedly).
Successful exploitation enables local privilege escalation to SYSTEM level, granting an attacker complete control over the affected Windows system. The vulnerability impacts confidentiality, integrity, and availability at a high level — an attacker could access sensitive data, modify system configurations, install malware, or disrupt system operations. While the attack vector is local, a threat actor who has already gained initial access (e.g., via phishing or another vulnerability) could leverage this flaw for post-exploitation privilege escalation and lateral movement (Feedly).
Microsoft released patches for all affected products on January 13, 2026, as part of the January 2026 Patch Tuesday update cycle. Administrators should update to the following minimum build versions: Windows 11 23H2 → 10.0.22631.6491, Windows 11 24H2 → 10.0.26100.7623, Windows 11 25H2 → 10.0.26200.7623, Windows Server 2022 → 10.0.20348.4648, Windows Server 2022 23H2 → 10.0.25398.2092, and Windows Server 2025 → 10.0.26100.32230. No configuration-based workarounds have been published; applying the security update is the only recommended remediation. Organizations should also restrict local user privileges where possible to reduce the attack surface (Microsoft MSRC, Feedly).
CVE-2026-20863 was covered as part of broader January 2026 Patch Tuesday roundups by several security outlets. Zero Day Initiative reviewed the January 2026 updates and noted the overall patch volume of 114 flaws including 3 zero-days, with Win32K privilege escalation bugs being a recurring theme (ZDI Blog). BleepingComputer and CyberSecurityNews also covered the January 2026 Patch Tuesday release, noting the breadth of fixes (BleepingComputer). Sophos and SANS ISC provided additional analyst commentary on the update batch (SANS ISC, Sophos Blog). No specific researcher commentary focused exclusively on this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."