Junglewise Threat Intelligence

CVE-2026-20962: Microsoft Windows Information Disclosure in DRTM

CVE-2026-20962 · Severity: medium · CVSS 4.4 · Published 2026-01-13

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows component responsible for verifying the integrity of the system's boot process. An attacker with high-level administrative access to a computer could exploit this to view sensitive information that should normally be protected. This could lead to the exposure of system secrets or other confidential data stored in memory.

Technical details

A vulnerability classified as CWE-908 (Use of Uninitialized Resource) exists in the Microsoft Windows Dynamic Root of Trust for Measurement (DRTM). The flaw allows a local attacker with high privileges (PR:H) to access uninitialized memory, potentially leading to the disclosure of sensitive information. The attack vector is local and requires no user interaction. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-01-13: advisory: Initial publication of the CVE detail

References

Related threats