
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20924 is a use-after-free vulnerability in Windows Management Services that allows an authorized local attacker to elevate privileges on affected systems. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2019, Windows Server 2022, and Windows Server 2025. It carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (Microsoft MSRC).
The vulnerability is rooted in a race condition (CWE-362) that leads to a use-after-free condition (CWE-416) within Windows Management Services. When concurrent execution paths improperly share a resource without adequate synchronization, memory that has already been freed can be accessed again, enabling an attacker to corrupt heap memory and redirect execution flow. Exploitation requires low-level local privileges and no user interaction, but the high attack complexity reflects the timing-dependent nature of triggering the race condition. The changed scope in the CVSS vector indicates that successful exploitation can impact resources beyond the vulnerable component itself (Microsoft MSRC).
Successful exploitation allows a low-privileged local attacker to escalate to SYSTEM-level privileges, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker who achieves SYSTEM access can install malware, modify or delete data, create new accounts, disable security controls, and potentially pivot to other systems on the network. The broad scope of affected products — spanning consumer Windows 10/11 and enterprise Windows Server editions — amplifies the potential organizational impact (Microsoft MSRC).
Microsoft released patches on January 13, 2026, as part of the January 2026 Patch Tuesday security update. Administrators should update affected systems to the following minimum versions: Windows 10 1809/Server 2019 → 10.0.17763.8276; Windows 10 21H2 → 10.0.19044.6809; Windows 10 22H2 → 10.0.19045.6809; Windows 11 23H2 → 10.0.22631.6491; Windows 11 24H2 → 10.0.26100.7623; Windows 11 25H2 → 10.0.26200.7623; Windows Server 2022 → 10.0.20348.4648; Windows Server 2022 23H2 → 10.0.25398.2092; Windows Server 2025 → 10.0.26100.32230. As a defense-in-depth measure, organizations should enforce the principle of least privilege to minimize the number of accounts that could be used to trigger this vulnerability, and ensure Windows Update or WSUS is configured for timely patch delivery (Microsoft MSRC).
The vulnerability was covered as part of broader January 2026 Patch Tuesday roundups by multiple security outlets. Zero Day Initiative noted it in their January 2026 security update review, and Rapid7 included it in their Patch Tuesday analysis (ZDI Blog, Rapid7 Blog). Sophos and BleepingComputer also covered the broader January 2026 Patch Tuesday release, which addressed 114 flaws including 3 zero-days, though CVE-2026-20924 itself did not receive significant individual attention given the absence of active exploitation (BleepingComputer, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."