CVE-2026-20931
vulnerability analysis and mitigation

Overview

CVE-2026-20931 is an elevation of privilege vulnerability in the Windows Telephony Service caused by external control of file name or path (CWE-73). It allows an authorized attacker with low privileges to escalate to SYSTEM-level access over an adjacent network without requiring user interaction. The vulnerability affects a broad range of Microsoft Windows operating systems, from Windows Server 2008 SP2 through Windows 11 25H2 and Windows Server 2025. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday. The CVSS v3.1 base score is 8.0 (High), assigned by Microsoft (Microsoft MSRC, Feedly).

Technical details

The root cause is classified as CWE-73 (External Control of File Name or Path), meaning the Windows Telephony Service improperly allows attacker-controlled input to influence file system path operations, enabling path traversal attacks. An attacker positioned on the same network segment (adjacent network) and holding low-privilege credentials can manipulate file name or path parameters passed to the Telephony Service, redirecting file operations to unintended locations and ultimately achieving privilege escalation to SYSTEM. No user interaction is required, and attack complexity is low. Detection and mitigation scripts have been published by Vicarius (Vicarius Detection, Vicarius Mitigation).

Impact

Successful exploitation results in full SYSTEM-level privilege escalation on the affected Windows host, with high impact to confidentiality, integrity, and availability. An attacker gaining SYSTEM privileges can read or exfiltrate sensitive data, modify or destroy system files, install malware or backdoors, and potentially use the compromised host as a pivot point for lateral movement within the network. The broad scope of affected products — spanning legacy systems like Windows Server 2008 through current releases like Windows Server 2025 and Windows 11 25H2 — significantly widens the potential attack surface (Microsoft MSRC, Feedly).

Exploitation steps

  1. Reconnaissance: Identify Windows systems on the local network segment running the Windows Telephony Service (tapisrv.dll/TAPI), using network scanning tools such as Nmap to enumerate open ports and service banners associated with TAPI (typically TCP port 135 and dynamic RPC ports).
  2. Obtain low-privilege access: Authenticate to the target system with any valid low-privilege domain or local account, as the vulnerability requires only "authorized attacker" (low privilege) access.
  3. Craft malicious path input: Prepare a path traversal payload targeting the Telephony Service's file name or path handling, exploiting the CWE-73 weakness to redirect file operations to privileged locations (e.g., system directories).
  4. Trigger the vulnerable code path: Submit the crafted input to the Windows Telephony Service via its RPC interface over the adjacent network, causing the service to process the attacker-controlled file path.
  5. Achieve SYSTEM-level privilege escalation: The manipulated file operation executes with elevated (SYSTEM) privileges, allowing the attacker to write malicious files, modify system configurations, or execute arbitrary code as SYSTEM (Microsoft MSRC, Vicarius Detection).

Indicators of compromise

  • Network: Unusual RPC/DCOM traffic from adjacent network hosts targeting the Windows Telephony Service (tapisrv); unexpected connections to TCP port 135 or dynamic RPC ports from non-administrative systems.
  • Logs: Windows Event Log entries showing unexpected privilege escalation events (Event ID 4672 – Special privileges assigned to new logon) associated with the Telephony Service process; anomalous TAPI-related errors in the System event log.
  • File System: Unexpected files written to privileged system directories (e.g., %SystemRoot%\System32) by the tapisrv.exe process; new or modified files in Telephony Service directories with timestamps coinciding with suspicious activity.
  • Process: Unusual child processes spawned by tapisrv.exe or svchost.exe hosting the Telephony Service; processes running as SYSTEM that were initiated from low-privilege user sessions.

Mitigation and workarounds

Microsoft released security updates on January 13, 2026 addressing CVE-2026-20931. Administrators should apply patches bringing affected systems to the following minimum versions: Windows Server 2008 SP2 (6.0.6003.23717), Windows Server 2008 R2 SP1 (6.1.7601.28117), Windows Server 2012 (6.2.9200.25868), Windows Server 2012 R2 (6.3.9600.22968), Windows 10 1607/Server 2016 (10.0.14393.8783), Windows 10 1809/Server 2019 (10.0.17763.8276), Windows Server 2022 (10.0.20348.4648), Windows Server 2022 23H2 (10.0.25398.2092), Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 11 23H2 (10.0.22631.6491), Windows 11 24H2 (10.0.26100.7623), Windows 11 25H2 (10.0.26200.7623), and Windows Server 2025 (10.0.26100.32230). As a workaround, implement network segmentation to restrict adjacent network access to systems running the Windows Telephony Service, and limit low-privilege user access to potentially targeted systems. For legacy Windows Server versions without ESU coverage, 0patch has released micropatches as an interim measure (Microsoft MSRC, 0patch Blog).

Community reactions

CVE-2026-20931 was covered as part of broader January 2026 Patch Tuesday roundups by BleepingComputer, Sophos, Lansweeper, and Petri, which collectively noted the large volume of vulnerabilities (113–114 CVEs) addressed that month (BleepingComputer, Sophos Blog). In April 2026, 0patch drew notable community attention by releasing micropatches specifically for this vulnerability targeting Windows Server versions not covered by Microsoft's ESU program, which was highlighted on Reddit's SecOpsDaily and Bluesky security communities (0patch Blog). Recorded Future's January 2026 CVE landscape report also referenced this vulnerability in the context of the month's broader threat environment (Recorded Future).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management