Junglewise Threat Intelligence

CVE-2026-20838: Microsoft Windows Kernel information disclosure in error messages

CVE-2026-20838 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Microsoft Windows 11 24h2, Microsoft Windows Server 2022 23h2, Microsoft Windows 11 Version 25H2, Microsoft Windows 11 23h2, Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows Kernel, the core component of the operating system, could allow a user already logged into a system to view sensitive information they should not have access to. This occurs because the system generates error messages that inadvertently include protected data. While an attacker must already have local access to the machine, this flaw could be used to gather intelligence for further attacks or compromise user privacy.

Technical details

An information disclosure vulnerability exists in the Microsoft Windows Kernel due to the improper generation of error messages (CWE-209). A locally authenticated attacker can exploit this by triggering specific system conditions that result in error messages containing sensitive kernel-mode information. The attack vector is local, requiring low privileges and no user interaction. Successful exploitation allows the attacker to disclose information that could potentially be used to bypass security mitigations like KASLR. Microsoft has released security updates for affected versions of Windows 11 and Windows Server.

Affected products

  • Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.6491
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.7623
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.7623
  • Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.4648
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.32230

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats