Junglewise Threat Intelligence

CVE-2026-20844: Microsoft Windows Clipboard Server use after free privilege escalation

CVE-2026-20844 · Severity: high · CVSS 7.4 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Clipboard Server, a core component that manages copying and pasting data between applications. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive files, install malicious software, or disrupt business operations.

Technical details

A use-after-free vulnerability exists in the Windows Clipboard Server component. The flaw is triggered by improper synchronization (race condition) during concurrent execution using shared resources. A local attacker can exploit this vulnerability to execute code with elevated privileges, potentially gaining SYSTEM-level access. The attack requires no prior user interaction or special privileges, though it does involve a high complexity (AC:H) likely due to the timing requirements of the race condition. Microsoft has released security updates for affected versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2016 All versions

Timeline

  • 2026-01-13: advisory: Initial publication of the vulnerability advisory.

References

Related threats