CVE-2026-20805
Microsoft · Published January 13, 2026
5.5
CVSS v3.1
MEDIUMCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
Affected Products
- Windows 10 1607 < 10.0.14393.8783
- Windows 10 1809 < 10.0.17763.8276
- Windows 10 21h2 < 10.0.19044.6809
- Windows 10 22h2 < 10.0.19045.6809
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N