CVE-2026-20875
vulnerability analysis and mitigation

Overview

CVE-2026-20875 is a NULL Pointer Dereference vulnerability (CWE-476) in the Windows Local Security Authority Subsystem Service (LSASS) that allows an unauthenticated remote attacker to cause a denial of service over a network. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects a wide range of Windows client and server versions from Windows Server 2008 through Windows 11 25H2 and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC, Feedly).

Technical details

The root cause is a NULL pointer dereference (CWE-476) within the LSASS process, which handles authentication and security policy enforcement on Windows systems. An unauthenticated attacker can send specially crafted network requests that trigger the dereference of a null pointer in LSASS, causing the service to crash. No privileges or user interaction are required, and the attack complexity is low, making it straightforward to trigger remotely. No public technical write-ups or proof-of-concept code detailing the specific vulnerable code path have been identified at this time (Microsoft MSRC, Feedly).

Impact

Successful exploitation causes LSASS to crash, resulting in a denial of service that disrupts authentication and login capabilities across the affected Windows system. Because LSASS is responsible for enforcing security policies and handling user authentication (including domain logins), its crash can prevent legitimate users from logging in and may force a system reboot. The impact is limited to availability — there is no confidentiality or integrity impact — but on domain controllers or authentication servers, the effect can cascade to disrupt access across an entire environment (Feedly).

Indicators of compromise

  • Logs: Unexpected LSASS process crashes recorded in the Windows Event Log (Event ID 1000 or 1001 in Application log, referencing lsass.exe); system reboots triggered by LSASS failure (Event ID 6008 — unexpected shutdown).
  • Network: Anomalous or malformed network traffic directed at authentication-related ports (e.g., TCP 445, 88, 135) from external or untrusted sources immediately preceding LSASS crashes.
  • Process: LSASS terminating unexpectedly without a corresponding administrative action; Windows Error Reporting generating crash dumps for lsass.exe in %SystemRoot%\Minidump or %LocalAppData%\CrashDumps.

Mitigation and workarounds

Microsoft released security updates on January 13, 2026, addressing this vulnerability. Administrators should apply the relevant cumulative updates to reach the following minimum patched versions: Windows 11 25H2 (10.0.26200.7623+), Windows 11 24H2 (10.0.26100.7623+), Windows 11 23H2 (10.0.22631.6491+), Windows 10 22H2 (10.0.19045.6809+), Windows 10 21H2 (10.0.19044.6809+), Windows 10 1809 (10.0.17763.8276+), Windows 10 1607 (10.0.14393.8783+), Windows Server 2025 (10.0.26100.32230+), Windows Server 2022 (10.0.20348.4648+), Windows Server 2022 23H2 (10.0.25398.2092+), Windows Server 2019 (10.0.17763.8276+), and Windows Server 2016 (10.0.14393.8783+). Prioritize patching domain controllers and other systems where LSASS availability is critical. As a temporary workaround where patching is not immediately possible, implement network-level access controls (e.g., firewall rules) to restrict access to authentication infrastructure from untrusted networks (Microsoft MSRC, Feedly).

Community reactions

The vulnerability was covered as part of broader January 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Cyber Security News, GBHackers, and Zero Day Initiative (ZDI), which noted the large patch batch of 114 flaws including 3 zero-days. CVE-2026-20875 itself did not receive significant standalone attention, as it was not among the zero-days and has no known active exploitation. SANS ISC and Lansweeper also published Patch Tuesday summaries referencing the update (BleepingComputer, ZDI, SANS ISC).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management