CVE-2026-20475: Medium severity Microsoft Windows vulnerability
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11004276
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20475?
CVE-2026-20475 has a risk rating of 41, indicating a significant potential impact.
How does CVE-2026-20475 exploit the system?
CVE-2026-20475 allows for a possible out of bounds write due to a missing bounds check, leading to local escalation of privilege.
Who can be affected by CVE-2026-20475?
CVE-2026-20475 affects Microsoft Windows systems where a malicious actor with System privilege can exploit the vulnerability.
Is user interaction required to exploit CVE-2026-20475?
No, user interaction is not needed for exploitation of CVE-2026-20475.
How do I fix CVE-2026-20475?
To fix CVE-2026-20475, you need to apply the patch identified by ALPS11004276.