
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20873 is a local privilege escalation vulnerability caused by a race condition in Windows Management Services. An authorized attacker with low privileges can exploit improper synchronization of shared resources to elevate privileges on the local system. It affects a wide range of Microsoft Windows versions including Windows 10 (1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2019, 2022, 2022 23H2, and Windows Server 2025. Microsoft disclosed and patched the vulnerability on January 13, 2026, as part of its monthly Patch Tuesday release. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The vulnerability is rooted in concurrent execution using a shared resource with improper synchronization (CWE-362: Race Condition) combined with a Use After Free condition (CWE-416) within Windows Management Services. An attacker can exploit a time-of-check to time-of-use (TOCTOU) race condition — a timing window during which a shared resource is accessed without proper locking — to manipulate memory and escalate privileges. Exploitation requires local access and low-level privileges (e.g., a standard user account), but no user interaction is needed. The changed scope indicator in the CVSS vector suggests the impact can extend beyond the initially compromised component (Microsoft MSRC, Feedly).
Successful exploitation allows an authorized but low-privileged local attacker to escalate to SYSTEM-level privileges, resulting in complete system compromise. This grants the attacker full control over confidentiality, integrity, and availability of the affected system — enabling unauthorized access to sensitive data, modification of system configurations, installation of malware or backdoors, and potential denial of service. The changed scope in the CVSS scoring indicates that the impact can extend beyond the Windows Management Services component itself, potentially affecting other system resources and facilitating lateral movement within a network (Microsoft MSRC, Feedly).
Microsoft released patches on January 13, 2026, as part of the January 2026 Patch Tuesday update. Affected systems should be updated to the following minimum build versions: Windows 10 1809 (10.0.17763.8276), Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 11 23H2 (10.0.22631.6491), Windows 11 24H2 (10.0.26100.7623), Windows 11 25H2 (10.0.26200.7623), Windows Server 2019 (10.0.17763.8276), Windows Server 2022 (10.0.20348.4648), Windows Server 2022 23H2 (10.0.25398.2092), and Windows Server 2025 (10.0.26100.32230). As interim measures, organizations should restrict local system access to authorized users only, implement Privileged Access Management (PAM) solutions, and monitor Windows Management Services for anomalous activity (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader January 2026 Patch Tuesday reporting, which addressed 114 flaws including 3 zero-days. Security outlets including BleepingComputer, Rapid7, Sophos, and Zero Day Initiative (ZDI) published roundup analyses of the January 2026 update cycle, noting the overall volume and severity of patches. CVE-2026-20873 was not individually highlighted as a critical concern given the absence of public exploits, but was noted in the context of privilege escalation risks across Windows platforms (BleepingComputer, ZDI, Rapid7, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."