Junglewise Threat Intelligence

CVE-2026-20854: Microsoft Windows LSASS use after free remote code execution

CVE-2026-20854 · Severity: high · CVSS 7.5 · Published 2026-01-13

Technologies: Microsoft Windows 11 24h2, Microsoft Windows Server 2025, Microsoft Windows 11 Version 25H2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Local Security Authority Subsystem Service (LSASS), which manages user logins and security policies. An authorized attacker could exploit this flaw to remotely execute malicious code on a target system. This could lead to a complete takeover of the affected server or workstation, potentially compromising sensitive data and disrupting business operations.

Technical details

This vulnerability is classified as a Use-After-Free (CWE-416) within the Local Security Authority Subsystem Service (LSASS). The flaw can be triggered over the network by an attacker who has already obtained low-privileged authentication on the target system. Due to the high complexity of the attack (AC:H), successful exploitation requires specific timing or environmental conditions to be met. If successfully exploited, the attacker can achieve remote code execution (RCE) with the high privileges associated with the LSASS process. Microsoft has released security updates to address this issue across affected versions of Windows 11 and Windows Server 2025.

Affected products

  • Microsoft Windows 11 Version 24H2 up to (excluding) 10.0.26100.7623
  • Microsoft Windows 11 Version 25H2 up to (excluding) 10.0.26200.7623
  • Microsoft Windows Server 2025 up to (excluding) 10.0.26100.32230

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory: Microsoft released the security update guide for this vulnerability.

References

Related threats