
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20929 is an improper access control vulnerability in Windows HTTP.sys that allows an authenticated, low-privileged attacker to elevate privileges over a network. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 23H2, Windows Server 2008 through 2022 (including 23H2 edition). The vulnerability carries a CVSS v3.1 base score of 7.5 (High), assigned by Microsoft (Microsoft MSRC). Research published after initial disclosure revealed the underlying mechanism involves Kerberos authentication relay via DNS CNAME abuse, enabling credential relay attacks across enterprise networks (Cymulate, CrowdStrike).
The vulnerability is classified as CWE-284 (Improper Access Control) in Windows HTTP.sys, the kernel-mode HTTP server driver used by IIS and other Windows services (Microsoft MSRC). Post-disclosure research identified the specific exploitation mechanism as a Kerberos authentication relay attack leveraging DNS CNAME records — an attacker can manipulate DNS CNAME entries to redirect Kerberos authentication requests, causing HTTP.sys to relay credentials to an attacker-controlled endpoint, effectively bypassing existing relay defenses (Cymulate, CrowdStrike). Exploitation requires the attacker to be an authenticated, low-privileged network user with the ability to influence DNS resolution (e.g., via CNAME manipulation), but requires no user interaction. The attack vector is network-based with high attack complexity, reflecting the DNS manipulation prerequisite (Microsoft MSRC).
Successful exploitation allows an authenticated attacker with low privileges to escalate to higher system privileges remotely over the network, potentially achieving full system compromise. The CVSS scoring reflects high confidentiality, integrity, and availability impact — meaning an attacker could gain unauthorized access to sensitive data, modify system configurations, and disrupt service availability (Microsoft MSRC). In Active Directory environments, the Kerberos relay technique could enable lateral movement by relaying credentials to other services, posing significant risk to enterprise networks (Cymulate, CrowdStrike).
http.sys or IIS worker processes (w3wp.exe); authentication attempts from service accounts to domain controllers at unusual times.Microsoft released patches on January 13, 2026 as part of the January 2026 Patch Tuesday. Affected systems should be updated to the following minimum versions: Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 10 1809 (10.0.17763.8276), Windows 10 1607 (10.0.14393.8783), Windows 11 23H2 (10.0.22631.6491), Windows Server 2019 (10.0.17763.8276), Windows Server 2016 (10.0.14393.8783), Windows Server 2022 (10.0.20348.4648), and Windows Server 2022 23H2 (10.0.25398.2092) (Microsoft MSRC). As interim mitigations, administrators should restrict DNS write permissions for low-privileged users, implement network access controls limiting which users can reach HTTP.sys services, enable Extended Protection for Authentication (EPA) on IIS, and monitor for anomalous DNS CNAME changes and Kerberos relay activity (CrowdStrike).
The Zero Day Initiative (ZDI) covered CVE-2026-20929 in its January 2026 Security Update Review, and BleepingComputer reported on it as part of the broader January 2026 Patch Tuesday coverage of 114 flaws (ZDI Blog, BleepingComputer). Cymulate and CrowdStrike published detailed threat intelligence reports on the Kerberos relay via DNS CNAME technique, generating significant community discussion on Reddit and security forums (Cymulate, CrowdStrike). The SANS Internet Storm Center also noted the vulnerability in its January 2026 Patch Tuesday diary (SANS ISC). Flare.io included it in post-patch Tuesday threat intelligence analysis, and WaterISAC flagged it as a priority vulnerability for critical infrastructure defenders.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."