MEDIUM

CVE-2026-20805

Microsoft Windows 10 1607 2026-01-13 CVSS v3.1
CVSS
5.5
KEV

Description

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Summary dbcve.org

CVE-2026-20805 is a local information disclosure vulnerability in Windows Desktop Windows Manager (DWM) that allows an authorized local attacker to access sensitive information that should be protected from unprivileged users.

Mitigation

Apply the relevant Microsoft Windows security update for Desktop Windows Manager through Windows Update or enterprise patch management systems.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

5.19%
Probability of exploitation in next 30 days
92.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE