Junglewise Threat Intelligence

CVE-2026-20811: Microsoft Windows Win32K type confusion privilege escalation

CVE-2026-20811 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Microsoft Windows 11 24h2, Microsoft Windows Server 2022 23h2, Microsoft Windows 11 Version 25H2, Microsoft Windows 11 23h2, Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Win32K component, which handles graphics and window management. An authorized user with low-level access can exploit this flaw to gain full administrative control over the system. This could allow an attacker to bypass security restrictions, access sensitive data, or install malicious software.

Technical details

This vulnerability is classified as a type confusion (CWE-843) and untrusted pointer dereference (CWE-822) within the Windows Win32K - ICOMP component. The flaw occurs when the system accesses a resource using an incompatible type, leading to memory corruption or improper execution flow. An attacker must have local access and be authenticated with low privileges (PR:L) to execute a specially crafted application. Successful exploitation allows the attacker to gain SYSTEM-level privileges. Microsoft has released security updates to address this issue across affected Windows 11 and Windows Server versions.

Affected products

  • Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.6491
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.7623
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.7623
  • Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.4648
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.32230

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats