CVE-2026-20935
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:57:03
- Zuletzt bearbeitet 16.01.2026 15:18:31
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.
CVE-2026-20874
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:57:02
- Zuletzt bearbeitet 15.01.2026 21:38:30
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20873
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:57:01
- Zuletzt bearbeitet 15.01.2026 21:39:34
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20871
- EPSS 0.04%
- Veröffentlicht 13.01.2026 17:57:00
- Zuletzt bearbeitet 15.01.2026 15:48:21
Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-20872
- EPSS 0.1%
- Veröffentlicht 13.01.2026 17:57:00
- Zuletzt bearbeitet 15.01.2026 15:50:13
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20870
- EPSS 0.04%
- Veröffentlicht 13.01.2026 17:56:59
- Zuletzt bearbeitet 15.01.2026 15:47:31
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2026-20867
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:56:58
- Zuletzt bearbeitet 15.01.2026 15:42:24
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20868
- EPSS 0.13%
- Veröffentlicht 13.01.2026 17:56:58
- Zuletzt bearbeitet 10.02.2026 15:16:05
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:56:57
- Zuletzt bearbeitet 15.01.2026 15:34:09
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2026-20866
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:56:57
- Zuletzt bearbeitet 15.01.2026 15:41:10
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.