
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20938 is an untrusted pointer dereference vulnerability in Windows Virtualization-Based Security (VBS) Enclave that allows an authorized local attacker to elevate privileges. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Windows 11 versions 23H2 (builds prior to 10.0.22631.6491), 24H2 (builds prior to 10.0.26100.7623), and 25H2 (builds prior to 10.0.26200.7623) on both x64 and ARM64 architectures. It carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-822 (Untrusted Pointer Dereference), meaning the Windows VBS Enclave component dereferences a pointer that can be controlled or influenced by an attacker-supplied value without adequate validation. VBS Enclave is a hardware-isolated execution environment leveraging virtualization technology to protect sensitive code and data; a flaw in its pointer handling allows a low-privileged local user to manipulate memory in a way that triggers privilege escalation. Exploitation requires local access and low privileges but no user interaction, making it a straightforward post-authentication escalation path (Microsoft MSRC, Feedly). The attack is mapped to CAPEC-129 (Pointer Manipulation) (Feedly).
Successful exploitation allows a low-privileged authenticated attacker to escalate to SYSTEM-level privileges on the affected Windows 11 system, resulting in high confidentiality, integrity, and availability impact. With SYSTEM access, an attacker could install malware, access or exfiltrate sensitive data, tamper with system configurations, and potentially move laterally within a network by leveraging the compromised host as a pivot point. The vulnerability affects both x64 and ARM64 architectures across multiple Windows 11 release channels (Feedly).
Microsoft released security updates on January 13, 2026, addressing this vulnerability. Administrators should apply the following updates: Windows 11 23H2 — update to build 10.0.22631.6491 or later; Windows 11 24H2 — update to build 10.0.26100.7623 or later; Windows 11 25H2 — update to build 10.0.26200.7623 or later. As a defense-in-depth measure, organizations should enforce least-privilege access principles, restrict local logon access to sensitive systems, and monitor for suspicious privilege escalation activity on affected endpoints (Microsoft MSRC, Feedly).
CVE-2026-20938 was covered as part of broader January 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Rapid7, Sophos, and GBHackers, which collectively noted Microsoft addressed 114 vulnerabilities including 3 zero-days in that release cycle (BleepingComputer, Rapid7, Sophos). No specific researcher commentary or notable social media discussion focused exclusively on this CVE was identified, consistent with its lack of public PoC or active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."