CVE-2026-20929
vulnerability analysis and mitigation

Overview

CVE-2026-20929 is an improper access control vulnerability in Windows HTTP.sys that allows an authenticated, low-privileged attacker to elevate privileges over a network. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 23H2, Windows Server 2008 through 2022 (including 23H2 edition). The vulnerability carries a CVSS v3.1 base score of 7.5 (High), assigned by Microsoft (Microsoft MSRC). Research published after initial disclosure revealed the underlying mechanism involves Kerberos authentication relay via DNS CNAME abuse, enabling credential relay attacks across enterprise networks (Cymulate, CrowdStrike).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control) in Windows HTTP.sys, the kernel-mode HTTP server driver used by IIS and other Windows services (Microsoft MSRC). Post-disclosure research identified the specific exploitation mechanism as a Kerberos authentication relay attack leveraging DNS CNAME records — an attacker can manipulate DNS CNAME entries to redirect Kerberos authentication requests, causing HTTP.sys to relay credentials to an attacker-controlled endpoint, effectively bypassing existing relay defenses (Cymulate, CrowdStrike). Exploitation requires the attacker to be an authenticated, low-privileged network user with the ability to influence DNS resolution (e.g., via CNAME manipulation), but requires no user interaction. The attack vector is network-based with high attack complexity, reflecting the DNS manipulation prerequisite (Microsoft MSRC).

Impact

Successful exploitation allows an authenticated attacker with low privileges to escalate to higher system privileges remotely over the network, potentially achieving full system compromise. The CVSS scoring reflects high confidentiality, integrity, and availability impact — meaning an attacker could gain unauthorized access to sensitive data, modify system configurations, and disrupt service availability (Microsoft MSRC). In Active Directory environments, the Kerberos relay technique could enable lateral movement by relaying credentials to other services, posing significant risk to enterprise networks (Cymulate, CrowdStrike).

Exploitation steps

  1. Reconnaissance: Identify target Windows systems running HTTP.sys-based services (e.g., IIS) that are joined to an Active Directory domain. Confirm the attacker has a low-privileged authenticated account on the network.
  2. DNS CNAME Manipulation: Leverage write access to DNS (e.g., via low-privileged AD user permissions on DNS zones) to create or modify a CNAME record pointing a legitimate hostname to an attacker-controlled machine.
  3. Trigger Kerberos Authentication: Cause the target HTTP.sys service to initiate a Kerberos authentication request to the CNAME-resolved hostname — for example, by sending a crafted HTTP request that causes the server to perform a callback or authentication to the manipulated DNS name.
  4. Relay Kerberos Credentials: Intercept the Kerberos authentication ticket relayed through HTTP.sys to the attacker-controlled endpoint using a relay tool (e.g., a modified Kerberos relay framework). The DNS CNAME causes HTTP.sys to bypass standard relay protections.
  5. Privilege Escalation: Use the relayed Kerberos ticket to authenticate to a higher-privileged service (e.g., LDAP, SMB, or HTTP on a domain controller), achieving elevated access or full domain compromise (Cymulate, CrowdStrike).

Indicators of compromise

  • Network: Unexpected Kerberos authentication requests (TGS-REQ/TGS-REP) from HTTP.sys processes to unusual or newly created hostnames; outbound HTTP/HTTPS connections from Windows servers to unfamiliar internal hosts resolved via CNAME records; anomalous NTLM or Kerberos relay traffic patterns on the network.
  • DNS: Newly created or recently modified DNS CNAME records pointing to internal or external attacker-controlled hosts; CNAME records resolving to IP addresses outside expected infrastructure.
  • Logs: Windows Security Event Log entries showing privilege escalation (Event ID 4672 — Special privileges assigned to new logon) from unexpected accounts; Kerberos service ticket requests (Event ID 4769) for unusual SPNs or hostnames; HTTP.sys or IIS logs showing requests triggering outbound authentication callbacks.
  • Process: Unusual child processes or network connections spawned by http.sys or IIS worker processes (w3wp.exe); authentication attempts from service accounts to domain controllers at unusual times.
  • File System: New or modified DNS zone files or registry entries related to DNS configuration changes (CrowdStrike, Cymulate).

Mitigation and workarounds

Microsoft released patches on January 13, 2026 as part of the January 2026 Patch Tuesday. Affected systems should be updated to the following minimum versions: Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 10 1809 (10.0.17763.8276), Windows 10 1607 (10.0.14393.8783), Windows 11 23H2 (10.0.22631.6491), Windows Server 2019 (10.0.17763.8276), Windows Server 2016 (10.0.14393.8783), Windows Server 2022 (10.0.20348.4648), and Windows Server 2022 23H2 (10.0.25398.2092) (Microsoft MSRC). As interim mitigations, administrators should restrict DNS write permissions for low-privileged users, implement network access controls limiting which users can reach HTTP.sys services, enable Extended Protection for Authentication (EPA) on IIS, and monitor for anomalous DNS CNAME changes and Kerberos relay activity (CrowdStrike).

Community reactions

The Zero Day Initiative (ZDI) covered CVE-2026-20929 in its January 2026 Security Update Review, and BleepingComputer reported on it as part of the broader January 2026 Patch Tuesday coverage of 114 flaws (ZDI Blog, BleepingComputer). Cymulate and CrowdStrike published detailed threat intelligence reports on the Kerberos relay via DNS CNAME technique, generating significant community discussion on Reddit and security forums (Cymulate, CrowdStrike). The SANS Internet Storm Center also noted the vulnerability in its January 2026 Patch Tuesday diary (SANS ISC). Flare.io included it in post-patch Tuesday threat intelligence analysis, and WaterISAC flagged it as a priority vulnerability for critical infrastructure defenders.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management