Junglewise Threat Intelligence

CVE-2026-20835: Microsoft Windows Capability Access Management Service out-of-bounds read

CVE-2026-20835 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Microsoft Windows 11 24h2, Microsoft Windows 11 Version 25H2, Microsoft Windows Server 2022, 23H2 Edition (Server Core installation), Microsoft Windows Server 2025. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Windows Capability Access Management Service, which manages how applications access hardware features like cameras or microphones. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that should be protected. This could lead to the unauthorized disclosure of system or user data, though it cannot be used to take over the computer or crash the system directly.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists within the Capability Access Management Service (camsvc) in multiple versions of Windows 11 and Windows Server. The flaw is triggered when the service improperly handles memory boundaries during data processing. An attacker with local access and low privileges can exploit this to read memory contents that are otherwise restricted, potentially leading to the disclosure of sensitive information. The attack requires local authentication but no user interaction. Microsoft has released security updates to address this issue by improving memory boundary checks.

Affected products

  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.7623
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.7623
  • Microsoft Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.0 to 10.0.25398.2092
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.32230

Timeline

  • 2026-01-13: advisory: Initial disclosure by Microsoft and NVD
  • 2026-01-13: disclosed

References

Related threats