Junglewise Threat Intelligence

CVE-2026-20859: Microsoft Windows Kernel-Mode Drivers use after free privilege escalation

CVE-2026-20859 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Microsoft Windows Server 2025, Microsoft Windows 11 24h2, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the core software drivers that manage hardware and system operations in Windows 11 and Windows Server 2025. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A use-after-free (UAF) vulnerability exists within the Windows Kernel-Mode Drivers (CWE-416). The flaw is triggered when the kernel attempts to access a memory location after it has been freed, which can be manipulated by a local attacker with low privileges. By successfully exploiting this condition, an attacker can execute arbitrary code in kernel mode, leading to a full local privilege escalation (LPE). The vulnerability affects Windows 11 versions 24H2 and 25H2, as well as Windows Server 2025. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows 11 Version 24H2 10.0.26100.0 up to 10.0.26100.7623
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 up to 10.0.26200.7623
  • Microsoft Windows Server 2025 10.0.26100.0 up to 10.0.26100.32230

Timeline

  • 2026-01-13: disclosed: Initial publication of the vulnerability advisory.
  • 2026-01-15: advisory: NIST initial analysis completed.

References

Related threats