CVE-2026-20936
vulnerability analysis and mitigation

Overview

CVE-2026-20936 is an out-of-bounds read vulnerability in Windows NDIS (Network Driver Interface Specification) that allows an authorized attacker to disclose sensitive information via a physical attack. It affects a broad range of Microsoft Windows and Windows Server versions, from Windows Server 2008 SP2 through Windows 11 25H2 and Windows Server 2025. The vulnerability was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 4.3 (Medium) (Microsoft MSRC, Feedly).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read), mapped to CAPEC-540 (Overread Buffers). An attacker with low-level privileges and physical access to the device can trigger an out-of-bounds read in the Windows NDIS kernel component, causing the system to read memory beyond the intended buffer boundary. This can expose kernel memory contents to the attacker. No user interaction is required, but the attack vector is strictly physical, meaning the attacker must have direct hardware access to the target system (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in an information disclosure impact only — there is no integrity or availability impact associated with this vulnerability. An authorized attacker with physical access can read kernel memory contents from the NDIS component, potentially exposing confidential system information such as cryptographic material, credentials, or other sensitive data resident in kernel memory. The scope is limited to the affected system and does not facilitate lateral movement or remote code execution (Microsoft MSRC, Feedly).

Mitigation and workarounds

Microsoft released patches on January 13, 2026, as part of the January 2026 Patch Tuesday. Administrators should apply the relevant cumulative updates to bring affected systems to the following minimum build versions: Windows 10 21H2/22H2 → 10.0.19044.6809 / 10.0.19045.6809; Windows 11 23H2 → 10.0.22631.6491; Windows 11 24H2 → 10.0.26100.7623; Windows 11 25H2 → 10.0.26200.7623; Windows Server 2016 → 10.0.14393.8783; Windows Server 2019 → 10.0.17763.8276; Windows Server 2022 → 10.0.20348.4648; Windows Server 2022 23H2 → 10.0.25398.2092; Windows Server 2025 → 10.0.26100.32230. As a complementary control, organizations should enforce strict physical access controls to limit who can interact directly with sensitive systems (Microsoft MSRC, Feedly).

Community reactions

The January 2026 Patch Tuesday was broadly covered by security outlets, with CVE-2026-20936 noted as one of 114 vulnerabilities addressed in that release cycle. Coverage from Zero Day Initiative, BleepingComputer, Sophos, and Lansweeper highlighted the overall patch batch, though this specific vulnerability received minimal individual attention due to its medium severity and physical-only attack vector (Zero Day Initiative, BleepingComputer, Sophos).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management