
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20872 is a spoofing vulnerability in Windows NTLM caused by external control of file name or path (CWE-73), allowing an unauthorized network attacker to perform spoofing attacks. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday security update. The vulnerability affects a broad range of Windows versions, from Windows Server 2008 SP2 through Windows 11 25H2 and Windows Server 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Microsoft MSRC, Feedly).
The root cause is classified as CWE-73 (External Control of File Name or Path), where Windows NTLM improperly allows externally controlled input to influence file or path references used during authentication. This flaw enables a network-based attacker to manipulate NTLM authentication flows, potentially redirecting credential exchanges to attacker-controlled resources — a technique consistent with NTLM relay or coercion attacks. Exploitation requires user interaction (e.g., a victim opening a malicious file or visiting a crafted resource), but no prior privileges are needed. Detection and mitigation scripts have been published by Vicarius (Vicarius Detection, Vicarius Mitigation).
Successful exploitation results in a high confidentiality impact — specifically, unauthorized disclosure of NTLM credentials or authentication material — with no direct integrity or availability impact. An attacker who captures or relays NTLM credentials could impersonate the victim user across the network, potentially enabling lateral movement to other systems that accept NTLM authentication. The broad scope of affected Windows versions (from legacy Server 2008 to current Windows 11 25H2) significantly widens the attack surface in enterprise environments (Microsoft MSRC, Feedly).
Microsoft released patches on January 13, 2026, addressing all affected versions. Key patched builds include: Windows Server 2008 SP2 (6.0.6003.23717+), Windows Server 2012 (6.2.9200.25868+), Windows Server 2012 R2 (6.3.9600.22968+), Windows Server 2016 (10.0.14393.8783+), Windows Server 2019 (10.0.17763.8276+), Windows 10 21H2 (10.0.19044.6809+), Windows 10 22H2 (10.0.19045.6809+), Windows 11 23H2 (10.0.22631.6491+), Windows 11 24H2 (10.0.26100.7623+), Windows 11 25H2 (10.0.26200.7623+), Windows Server 2022 (10.0.20348.4648+), Windows Server 2022 23H2 (10.0.25398.2092+), and Windows Server 2025 (10.0.26100.32230+). As workarounds, organizations should consider disabling NTLM authentication where feasible and migrating to Kerberos, implementing network segmentation to limit NTLM exposure, and blocking outbound SMB traffic at the perimeter. Vicarius has published detection and mitigation scripts for environments requiring interim protection (Microsoft MSRC, Vicarius Mitigation).
CVE-2026-20872 was covered as part of broader January 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Cybersecurity News, GBHackers, and Zero Day Initiative (ZDI), which noted the patch addressed 114 vulnerabilities including 3 zero-days — though this CVE was not among the zero-days (BleepingComputer, ZDI Blog). SANS ISC also covered the January 2026 update in its diary (SANS ISC). NSFOCUS issued a high-risk vulnerability notice for Microsoft's January update, referencing this CVE among others (NSFOCUS). Community reaction was measured, with no significant alarm given the lack of active exploitation and the Medium CVSS score.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."