Junglewise Threat Intelligence

CVE-2026-20805: Microsoft Windows Desktop Window Manager information disclosure

CVE-2026-20805 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2026-01-13

Technologies: Microsoft Windows, Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Microsoft Windows Desktop Window Manager, the component responsible for rendering the visual interface of the operating system. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that should otherwise be protected. While this does not allow for direct control of the system, it could lead to the exposure of private data or credentials, and the vulnerability is reportedly being exploited in the wild.

Technical details

An information disclosure vulnerability (CWE-200) exists in the Microsoft Desktop Window Manager (DWM). The flaw allows an authorized attacker with local access to the system to disclose sensitive information without requiring user interaction. The vulnerability is categorized as medium severity with a CVSS 3.1 score of 5.5, primarily impacting confidentiality. Despite the medium severity, CISA has added this to the Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Microsoft has released security updates for affected versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2012 All versions

Timeline

  • 2026-01-13: advisory: Initial disclosure by Microsoft and NVD
  • 2026-01-13: kev added: Added to CISA KEV catalog due to active exploitation
  • 2026-02-03: patched: CISA deadline for federal agencies to apply patches

References

Related threats