- EPSS 0.79%
- Veröffentlicht 13.01.2026 17:57:03
- Zuletzt bearbeitet 16.01.2026 15:06:39
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
CVE-2026-20935
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:57:03
- Zuletzt bearbeitet 16.01.2026 15:18:31
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.
CVE-2026-20874
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:57:02
- Zuletzt bearbeitet 15.01.2026 21:38:30
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20929
- EPSS 0.05%
- Veröffentlicht 13.01.2026 17:57:02
- Zuletzt bearbeitet 16.01.2026 15:05:21
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
CVE-2026-20873
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:57:01
- Zuletzt bearbeitet 15.01.2026 21:39:34
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20872
- EPSS 0.1%
- Veröffentlicht 13.01.2026 17:57:00
- Zuletzt bearbeitet 15.01.2026 15:50:13
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20870
- EPSS 0.04%
- Veröffentlicht 13.01.2026 17:56:59
- Zuletzt bearbeitet 15.01.2026 15:47:31
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2026-20868
- EPSS 0.13%
- Veröffentlicht 13.01.2026 17:56:58
- Zuletzt bearbeitet 10.02.2026 15:16:05
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2026-20861
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:56:55
- Zuletzt bearbeitet 15.01.2026 15:31:53
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-20853
- EPSS 0.02%
- Veröffentlicht 13.01.2026 17:56:54
- Zuletzt bearbeitet 15.01.2026 13:28:14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.