Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5034 articles · 188809 vulns · 37/41 feeds (7d)
← Back to list
5.5
CVE-2026-20805KEVEXPLOITEDPATCHED
microsoft · windows_10_1607

Desktop Window Manager Information Disclosure Vulnerability

Description

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Affected Products

VendorProductVersions
microsoftwindows_10_160710.0.14393.0, 10.0.17763.0, 10.0.19044.0, 10.0.19045.0, 10.0.22631.0, 10.0.22631.0, 10.0.26100.0, 10.0.26200.0, 6.2.9200.0, 6.2.9200.0, 6.3.9600.0, 6.3.9600.0, 10.0.14393.0, 10.0.14393.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0, 10.0.25398.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftwindows_server_2022cve_cpe95%
microsoftwindows_10_1809cve_cpe95%
microsoftwindows_server_2022_23h2cve_cpe95%
microsoftwindows_server_2012cve_cpe95%
microsoftwindows_server_2016cve_cpe95%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20805(vendor-advisory, patch)

Related News (1 articles)

Tier B
JPCERT/CC
Security Alert: Microsoft Releases January 2026 Security Updates
→ No new info (linked only)
CVSS 3.15.5 MEDIUM
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
10.0.14393.878310.0.17763.827610.0.19044.680910.0.19045.680910.0.22631.649110.0.26100.762310.0.26200.762310.0.20348.464810.0.25398.2092
CWECWE-200
PublishedJan 13, 2026
Last enriched132d agov2
Trending Score0
Source articles1
Independent1
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-68820EXPKEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Trending: 156
CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 155
HIGHCVE-2026-45659EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 155
HIGHCVE-2026-50656EXP
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 99
CRITICALCVE-2026-50522EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 77

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Jan 13, 2026
Added to CISA KEV
Jan 13, 2026
Discovered by ZDM
Apr 1, 2026
Updated: cweIds
Apr 1, 2026
Actively Exploited
Jul 30, 2026
Exploit Available
Jul 30, 2026
Patch Available
Jul 30, 2026

Version History

v2
Last enriched 132d ago
v2Tier B132d ago

Updated vendor to Microsoft Corporation, product to Desktop Window Manager, severity to HIGH, and added new CWE-94.

cweIds
via JPCERT/CC
v1132d ago

Initial creation