CVE-2026-20935
vulnerability analysis and mitigation

Overview

CVE-2026-20935 is an untrusted pointer dereference vulnerability in Windows Virtualization-Based Security (VBS) Enclave that allows a local, unauthorized attacker to disclose sensitive information. It affects Windows 11 versions 23H2, 24H2, and 25H2 on both x64 and ARM64 architectures. The vulnerability was disclosed by Microsoft on January 13, 2026, as part of the January 2026 Patch Tuesday release. It carries a CVSS v3.1 base score of 6.2 (Medium), assigned by Microsoft (Microsoft MSRC, Feedly).

Technical details

The root cause is classified as CWE-822 (Untrusted Pointer Dereference), where the VBS Enclave component fails to properly validate pointer values before dereferencing them, allowing an attacker to influence the memory address being read. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), meaning any process running on the affected system could potentially trigger the vulnerability. Exploitation involves manipulating pointer values passed to or within the VBS Enclave to cause the system to read from attacker-influenced memory locations, resulting in disclosure of sensitive enclave memory contents. No public proof-of-concept or technical write-up has been identified at this time (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in high-impact confidentiality loss, as an attacker with local access can read sensitive memory contents from within the VBS Enclave without requiring elevated privileges or user interaction. The integrity and availability of the system are not affected. Because VBS Enclaves are designed to protect sensitive data (such as cryptographic keys or credentials) from the rest of the OS, unauthorized disclosure from this component could expose highly sensitive information that the enclave was specifically designed to safeguard (Feedly).

Mitigation and workarounds

Microsoft released a security update on January 13, 2026, addressing this vulnerability. Administrators should apply the following patched builds: Windows 11 23H2 — version 10.0.22631.6491 or later; Windows 11 24H2 — version 10.0.26100.7623 or later; Windows 11 25H2 — version 10.0.26200.7623 or later. No configuration-based workarounds have been published; applying the security update via Windows Update or WSUS is the recommended remediation (Microsoft MSRC, Feedly).

Community reactions

The vulnerability was covered as part of broader January 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Rapid7, Sophos, Lansweeper, and Petri, which collectively noted the 114 CVEs addressed in that release. No specific researcher commentary or notable social media discussion focused exclusively on CVE-2026-20935 has been identified, consistent with its medium severity rating and lack of active exploitation (BleepingComputer, Rapid7, Sophos).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management