CVE-2026-20441: Medium severity Microsoft MAE vulnerability
In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10432500; Issue ID: MSV-5803.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20441?
CVE-2026-20441 has a high severity level due to the potential for local escalation of privilege.
How do I fix CVE-2026-20441?
To fix CVE-2026-20441, apply the patch identified by ID ALPS10432500 immediately.
What impact does CVE-2026-20441 have on affected systems?
CVE-2026-20441 allows a malicious actor with system privilege to perform an out-of-bounds write, which can lead to further exploitation.
Is user interaction required for exploiting CVE-2026-20441?
No, user interaction is not needed for exploiting CVE-2026-20441 as it can be exploited locally by an attacker with system privilege.
Which software is affected by CVE-2026-20441?
CVE-2026-20441 affects Microsoft MAE and certain versions of Google Android, particularly version 15.0.