Security
Loading…

CVE-2026-20805

MEDIUMCVSS 5.5Known Exploited
Description

Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.

Timeline
Published:January 13th, 2026 6:16 PM
Last modified:July 30th, 2026 9:16 PM
Added to KEV:January 13th, 2026
CVSS Scoring

CVSS v3: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Software
From NVD CPE configuration data

Vendors

microsoft

Products

windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2012windows_server_2016windows_server_2019windows_server_2022windows_server_2022_23h2windows_server_2025
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute