Junglewise Threat Intelligence

CVE-2026-20936: Microsoft Windows NDIS out-of-bounds read

CVE-2026-20936 · Severity: medium · CVSS 4.3 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows Server 2008 R2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Network Driver Interface Specification (NDIS), a critical component that manages how the operating system communicates with network hardware. An attacker with physical access to a device and basic user credentials could exploit this flaw to view sensitive information stored in the system's memory. While the risk is mitigated by the requirement for physical proximity, it could lead to the unauthorized disclosure of private data.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Microsoft Windows Network Driver Interface Specification (NDIS). The flaw is triggered when the component improperly handles memory buffers during network operations. An attacker must have physical access to the target machine and possess valid low-privileged credentials to exploit this vulnerability. Successful exploitation allows the attacker to read data from memory locations outside of the intended buffer, potentially leading to the disclosure of sensitive kernel or system information. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2008 R2 Service Pack 1

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats