CVE-2026-20870
- EPSS 0.05%
- Veröffentlicht 13.01.2026 17:56:59
- Zuletzt bearbeitet 15.01.2026 15:47:31
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2026-20867
- EPSS 0.04%
- Veröffentlicht 13.01.2026 17:56:58
- Zuletzt bearbeitet 15.01.2026 15:42:24
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20868
- EPSS 0.1%
- Veröffentlicht 13.01.2026 17:56:58
- Zuletzt bearbeitet 15.01.2026 15:45:10
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- EPSS 0.05%
- Veröffentlicht 13.01.2026 17:56:57
- Zuletzt bearbeitet 15.01.2026 15:34:09
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2026-20866
- EPSS 0.04%
- Veröffentlicht 13.01.2026 17:56:57
- Zuletzt bearbeitet 15.01.2026 15:41:10
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20862
- EPSS 0.04%
- Veröffentlicht 13.01.2026 17:56:56
- Zuletzt bearbeitet 15.01.2026 15:33:07
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.
CVE-2026-20861
- EPSS 0.04%
- Veröffentlicht 13.01.2026 17:56:55
- Zuletzt bearbeitet 15.01.2026 15:31:53
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20853
- EPSS 0.05%
- Veröffentlicht 13.01.2026 17:56:54
- Zuletzt bearbeitet 15.01.2026 13:28:14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.
CVE-2026-20854
- EPSS 0.07%
- Veröffentlicht 13.01.2026 17:56:54
- Zuletzt bearbeitet 15.01.2026 13:27:10
Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.
CVE-2026-20848
- EPSS 0.06%
- Veröffentlicht 13.01.2026 17:56:53
- Zuletzt bearbeitet 15.01.2026 14:03:20
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.