Junglewise Threat Intelligence

CVE-2026-20847: Microsoft Windows Shell information disclosure and spoofing

CVE-2026-20847 · Severity: medium · CVSS 6.5 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows Server 2008 R2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Shell, the graphical interface used to manage files and applications on Windows computers. An authorized user on the network could exploit this flaw to access sensitive information that they are not supposed to see. This could lead to further attacks, such as impersonating other users or systems on the network. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.

Technical details

An information disclosure vulnerability (CWE-200) exists in the Windows Shell component. The flaw allows an authenticated attacker with network access to expose sensitive information, which can subsequently be leveraged to perform network spoofing. The vulnerability is rated with a CVSS 3.1 base score of 6.5, indicating that while it requires prior authentication (PR:L), it does not require user interaction (UI:N) and has a high impact on confidentiality (C:H). Microsoft has released patches for affected versions of Windows 10, Windows 11, and Windows Server 2008 R2.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2008 R2 Service Pack 1

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats