
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20936 is an out-of-bounds read vulnerability in Windows NDIS (Network Driver Interface Specification) that allows an authorized attacker to disclose sensitive information via a physical attack. It affects a broad range of Microsoft Windows and Windows Server versions, from Windows Server 2008 SP2 through Windows 11 25H2 and Windows Server 2025. The vulnerability was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 4.3 (Medium) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), mapped to CAPEC-540 (Overread Buffers). An attacker with low-level privileges and physical access to the device can trigger an out-of-bounds read in the Windows NDIS kernel component, causing the system to read memory beyond the intended buffer boundary. This can expose kernel memory contents to the attacker. No user interaction is required, but the attack vector is strictly physical, meaning the attacker must have direct hardware access to the target system (Microsoft MSRC, Feedly).
Successful exploitation results in an information disclosure impact only — there is no integrity or availability impact associated with this vulnerability. An authorized attacker with physical access can read kernel memory contents from the NDIS component, potentially exposing confidential system information such as cryptographic material, credentials, or other sensitive data resident in kernel memory. The scope is limited to the affected system and does not facilitate lateral movement or remote code execution (Microsoft MSRC, Feedly).
Microsoft released patches on January 13, 2026, as part of the January 2026 Patch Tuesday. Administrators should apply the relevant cumulative updates to bring affected systems to the following minimum build versions: Windows 10 21H2/22H2 → 10.0.19044.6809 / 10.0.19045.6809; Windows 11 23H2 → 10.0.22631.6491; Windows 11 24H2 → 10.0.26100.7623; Windows 11 25H2 → 10.0.26200.7623; Windows Server 2016 → 10.0.14393.8783; Windows Server 2019 → 10.0.17763.8276; Windows Server 2022 → 10.0.20348.4648; Windows Server 2022 23H2 → 10.0.25398.2092; Windows Server 2025 → 10.0.26100.32230. As a complementary control, organizations should enforce strict physical access controls to limit who can interact directly with sensitive systems (Microsoft MSRC, Feedly).
The January 2026 Patch Tuesday was broadly covered by security outlets, with CVE-2026-20936 noted as one of 114 vulnerabilities addressed in that release cycle. Coverage from Zero Day Initiative, BleepingComputer, Sophos, and Lansweeper highlighted the overall patch batch, though this specific vulnerability received minimal individual attention due to its medium severity and physical-only attack vector (Zero Day Initiative, BleepingComputer, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."