CVE-2026-20456: Medium severity Microsoft Windows WLAN STA Driver vulnerability
In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480851; Issue ID: MSV-6338.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch WCNCR00480851 - Compensating control
Mitigate the risk of local denial of service by restricting local user execution privileges where possible until the wlan STA driver patch WCNCR00480851 (Issue ID MSV-6338) is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20456?
CVE-2026-20456 has a medium severity rating of 5.5 according to the CVSS 3.1 score.
How do I fix CVE-2026-20456?
To fix CVE-2026-20456, users should apply the patch identified as WCNCR00480851.
What can be the impact of CVE-2026-20456?
CVE-2026-20456 can lead to a local denial of service, potentially causing a system crash.
Which software is affected by CVE-2026-20456?
CVE-2026-20456 affects the Microsoft Windows WLAN STA Driver and various MediaTek firmware versions including Mt7902, Mt7920, Mt7921, Mt7922, Mt7925, and Mt7927.
Is user interaction required to exploit CVE-2026-20456?
User interaction is not required to exploit CVE-2026-20456, but user execution privileges are needed.