
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20931 is an elevation of privilege vulnerability in the Windows Telephony Service caused by external control of file name or path (CWE-73). It allows an authorized attacker with low privileges to escalate to SYSTEM-level access over an adjacent network without requiring user interaction. The vulnerability affects a broad range of Microsoft Windows operating systems, from Windows Server 2008 SP2 through Windows 11 25H2 and Windows Server 2025. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday. The CVSS v3.1 base score is 8.0 (High), assigned by Microsoft (Microsoft MSRC, Feedly).
The root cause is classified as CWE-73 (External Control of File Name or Path), meaning the Windows Telephony Service improperly allows attacker-controlled input to influence file system path operations, enabling path traversal attacks. An attacker positioned on the same network segment (adjacent network) and holding low-privilege credentials can manipulate file name or path parameters passed to the Telephony Service, redirecting file operations to unintended locations and ultimately achieving privilege escalation to SYSTEM. No user interaction is required, and attack complexity is low. Detection and mitigation scripts have been published by Vicarius (Vicarius Detection, Vicarius Mitigation).
Successful exploitation results in full SYSTEM-level privilege escalation on the affected Windows host, with high impact to confidentiality, integrity, and availability. An attacker gaining SYSTEM privileges can read or exfiltrate sensitive data, modify or destroy system files, install malware or backdoors, and potentially use the compromised host as a pivot point for lateral movement within the network. The broad scope of affected products — spanning legacy systems like Windows Server 2008 through current releases like Windows Server 2025 and Windows 11 25H2 — significantly widens the potential attack surface (Microsoft MSRC, Feedly).
%SystemRoot%\System32) by the tapisrv.exe process; new or modified files in Telephony Service directories with timestamps coinciding with suspicious activity.tapisrv.exe or svchost.exe hosting the Telephony Service; processes running as SYSTEM that were initiated from low-privilege user sessions.Microsoft released security updates on January 13, 2026 addressing CVE-2026-20931. Administrators should apply patches bringing affected systems to the following minimum versions: Windows Server 2008 SP2 (6.0.6003.23717), Windows Server 2008 R2 SP1 (6.1.7601.28117), Windows Server 2012 (6.2.9200.25868), Windows Server 2012 R2 (6.3.9600.22968), Windows 10 1607/Server 2016 (10.0.14393.8783), Windows 10 1809/Server 2019 (10.0.17763.8276), Windows Server 2022 (10.0.20348.4648), Windows Server 2022 23H2 (10.0.25398.2092), Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 11 23H2 (10.0.22631.6491), Windows 11 24H2 (10.0.26100.7623), Windows 11 25H2 (10.0.26200.7623), and Windows Server 2025 (10.0.26100.32230). As a workaround, implement network segmentation to restrict adjacent network access to systems running the Windows Telephony Service, and limit low-privilege user access to potentially targeted systems. For legacy Windows Server versions without ESU coverage, 0patch has released micropatches as an interim measure (Microsoft MSRC, 0patch Blog).
CVE-2026-20931 was covered as part of broader January 2026 Patch Tuesday roundups by BleepingComputer, Sophos, Lansweeper, and Petri, which collectively noted the large volume of vulnerabilities (113–114 CVEs) addressed that month (BleepingComputer, Sophos Blog). In April 2026, 0patch drew notable community attention by releasing micropatches specifically for this vulnerability targeting Windows Server versions not covered by Microsoft's ESU program, which was highlighted on Reddit's SecOpsDaily and Bluesky security communities (0patch Blog). Recorded Future's January 2026 CVE landscape report also referenced this vulnerability in the context of the month's broader threat environment (Recorded Future).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."