Junglewise Threat Intelligence

CVE-2026-20819: Microsoft Windows VBS Enclave untrusted pointer dereference

CVE-2026-20819 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Microsoft Windows 11 24h2, Microsoft Windows 11 Version 25H2, Microsoft Windows 11 23h2. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Virtualization-Based Security (VBS) Enclave, a feature designed to protect sensitive data by isolating it from the rest of the operating system. An attacker who already has basic access to a computer could exploit this flaw to view protected information that should otherwise be inaccessible. While this does not allow an attacker to take control of the system or delete files, it could lead to the exposure of confidential data.

Technical details

An untrusted pointer dereference vulnerability (CWE-822) exists within the Windows Virtualization-Based Security (VBS) Enclave. The flaw allows a locally authenticated attacker with low privileges to bypass isolation boundaries and disclose sensitive information from the enclave's memory. The attack vector is local, requiring the attacker to execute a specially crafted application on the target system. Microsoft has released security updates for affected versions of Windows 11 to address this issue.

Affected products

  • Microsoft Windows 11 Version 23H2 up to (excluding) 10.0.22631.6491
  • Microsoft Windows 11 Version 24H2 up to (excluding) 10.0.26100.7623
  • Microsoft Windows 11 Version 25H2 up to (excluding) 10.0.26200.7623

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats