Junglewise Threat Intelligence

CVE-2026-20862: Microsoft Windows Management Services information disclosure

CVE-2026-20862 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows 10 Version 21H2, Microsoft Windows Server 2019, Microsoft Windows 10 Version 1809, Microsoft Windows 10 Version 22H2, Microsoft Windows 11 Version 23H2, Microsoft Windows 11, Microsoft Windows 11 Version 24H2. Vendors: Microsoft.

Executive brief

A security vulnerability in Windows Management Services could allow a user who already has access to a computer to view sensitive information they are not authorized to see. This component is responsible for managing system configurations and operations across the Windows operating system. An exploit could lead to the exposure of confidential system data, potentially aiding further attacks or compromising privacy.

Technical details

An information disclosure vulnerability (CWE-200) exists in Windows Management Services. The flaw allows an authenticated attacker with local access to the system to disclose sensitive information. The attack vector is local (AV:L) and requires low privileges (PR:L) with no user interaction (UI:N). Successful exploitation results in high confidentiality impact (C:H) but does not affect system integrity or availability. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.8276
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.6809
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.6809
  • Microsoft Windows 11 Version 22H2 10.0.22621.0 to 10.0.22621.6491
  • Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.6491
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.7623
  • Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.8276
  • Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.3210

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats