CVE-2026-20872
vulnerability analysis and mitigation

Overview

CVE-2026-20872 is a spoofing vulnerability in Windows NTLM caused by external control of file name or path (CWE-73), allowing an unauthorized network attacker to perform spoofing attacks. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday security update. The vulnerability affects a broad range of Windows versions, from Windows Server 2008 SP2 through Windows 11 25H2 and Windows Server 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Microsoft MSRC, Feedly).

Technical details

The root cause is classified as CWE-73 (External Control of File Name or Path), where Windows NTLM improperly allows externally controlled input to influence file or path references used during authentication. This flaw enables a network-based attacker to manipulate NTLM authentication flows, potentially redirecting credential exchanges to attacker-controlled resources — a technique consistent with NTLM relay or coercion attacks. Exploitation requires user interaction (e.g., a victim opening a malicious file or visiting a crafted resource), but no prior privileges are needed. Detection and mitigation scripts have been published by Vicarius (Vicarius Detection, Vicarius Mitigation).

Impact

Successful exploitation results in a high confidentiality impact — specifically, unauthorized disclosure of NTLM credentials or authentication material — with no direct integrity or availability impact. An attacker who captures or relays NTLM credentials could impersonate the victim user across the network, potentially enabling lateral movement to other systems that accept NTLM authentication. The broad scope of affected Windows versions (from legacy Server 2008 to current Windows 11 25H2) significantly widens the attack surface in enterprise environments (Microsoft MSRC, Feedly).

Exploitation steps

  1. Reconnaissance: Identify target Windows systems running unpatched versions (e.g., Windows 10/11, Windows Server 2016–2025) using network scanning tools such as Nmap or asset inventory platforms.
  2. Craft malicious resource: Prepare a file or network resource (e.g., a UNC path, malicious document, or web link) that, when accessed by a victim, triggers an NTLM authentication request to an attacker-controlled server.
  3. Deliver lure to victim: Socially engineer the target user into opening the malicious file or navigating to the crafted resource — for example, via a phishing email containing a link or attachment that references the attacker's server path.
  4. Capture NTLM credentials: Use a tool such as Responder to intercept the NTLM authentication challenge/response sent by the victim's system when it attempts to authenticate to the attacker-controlled path.
  5. Relay or crack credentials: Either relay the captured NTLM hash to another internal service (using tools like ntlmrelayx) to authenticate as the victim, or attempt offline cracking of the Net-NTLMv2 hash to recover the plaintext password for further use (Vicarius Detection).

Indicators of compromise

  • Network: Unexpected outbound SMB (TCP 445) or HTTP connections from client workstations to external or unusual internal IP addresses; NTLM authentication attempts to unknown or external hosts.
  • Logs: Windows Security Event Log entries (Event ID 4776 — NTLM authentication) showing authentication attempts to unfamiliar or external servers; Event ID 4624/4625 with NTLM logon type from unexpected sources.
  • File System: Presence of malicious documents or shortcut files (.lnk, .url, .scf) referencing UNC paths pointing to external or attacker-controlled servers.
  • Process: Unusual processes initiating network connections (e.g., Office applications, Explorer) making outbound SMB or WebDAV requests to external IPs (Vicarius Detection).

Mitigation and workarounds

Microsoft released patches on January 13, 2026, addressing all affected versions. Key patched builds include: Windows Server 2008 SP2 (6.0.6003.23717+), Windows Server 2012 (6.2.9200.25868+), Windows Server 2012 R2 (6.3.9600.22968+), Windows Server 2016 (10.0.14393.8783+), Windows Server 2019 (10.0.17763.8276+), Windows 10 21H2 (10.0.19044.6809+), Windows 10 22H2 (10.0.19045.6809+), Windows 11 23H2 (10.0.22631.6491+), Windows 11 24H2 (10.0.26100.7623+), Windows 11 25H2 (10.0.26200.7623+), Windows Server 2022 (10.0.20348.4648+), Windows Server 2022 23H2 (10.0.25398.2092+), and Windows Server 2025 (10.0.26100.32230+). As workarounds, organizations should consider disabling NTLM authentication where feasible and migrating to Kerberos, implementing network segmentation to limit NTLM exposure, and blocking outbound SMB traffic at the perimeter. Vicarius has published detection and mitigation scripts for environments requiring interim protection (Microsoft MSRC, Vicarius Mitigation).

Community reactions

CVE-2026-20872 was covered as part of broader January 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Cybersecurity News, GBHackers, and Zero Day Initiative (ZDI), which noted the patch addressed 114 vulnerabilities including 3 zero-days — though this CVE was not among the zero-days (BleepingComputer, ZDI Blog). SANS ISC also covered the January 2026 update in its diary (SANS ISC). NSFOCUS issued a high-risk vulnerability notice for Microsoft's January update, referencing this CVE among others (NSFOCUS). Community reaction was measured, with no significant alarm given the lack of active exploitation and the Medium CVSS score.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management