
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20874 is a local privilege escalation vulnerability caused by a race condition in Windows Management Services. It allows an authorized attacker with low privileges to elevate privileges locally through improper synchronization of shared resources. The vulnerability was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday. Affected products include Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2), Windows Server 2019, Windows Server 2022, Windows Server 2022 23H2, and Windows Server 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The vulnerability is rooted in two related weaknesses: CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition) and CWE-416 (Use After Free), both attributed by Microsoft (Microsoft MSRC). The attack vector is local, requiring low privileges and no user interaction, but with high attack complexity — suggesting the attacker must win a timing-sensitive race condition to trigger the flaw. The scope is changed, meaning a successful exploit can affect resources beyond the vulnerable component itself, consistent with a privilege escalation to SYSTEM level. No public proof-of-concept or detailed technical write-up has been identified at this time.
Successful exploitation allows a low-privileged local attacker to escalate privileges to SYSTEM level on the affected Windows host, granting complete control over the system. This impacts confidentiality, integrity, and availability at a high level, as an attacker with SYSTEM privileges can access all data, modify system configurations, install malware, disable security controls, and potentially pivot to other systems on the network (Microsoft MSRC, Feedly).
Microsoft released patches on January 13, 2026, as part of the January 2026 Patch Tuesday update cycle. Administrators should apply the following patched builds: Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 10 1809 (10.0.17763.8276), Windows 11 23H2 (10.0.22631.6491), Windows 11 24H2 (10.0.26100.7623), Windows 11 25H2 (10.0.26200.7623), Windows Server 2019 (10.0.17763.8276), Windows Server 2022 (10.0.20348.4648), Windows Server 2022 23H2 (10.0.25398.2092), and Windows Server 2025 (10.0.26100.32230) (Microsoft MSRC). As a defense-in-depth measure, restrict local interactive and remote desktop access to trusted users only, and monitor security logs for unusual privilege escalation activity.
CVE-2026-20874 was covered as part of broader January 2026 Patch Tuesday roundups by several security outlets. Zero Day Initiative reviewed the January 2026 updates (ZDI Blog), and BleepingComputer reported on the full patch batch fixing 114 flaws (BleepingComputer). Rapid7 and Sophos also published Patch Tuesday analyses covering this vulnerability among others. Community reaction has been measured, with no significant alarm given the local-only attack vector and high complexity requirement.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."