CVE-2026-20805: Microsoft Windows Information Disclosure Vulnerability
Desktop Window Manager Information Disclosure Vulnerability
Other sources
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
— Microsoft
Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8783Patch KB5073722 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22968Patch KB5073696 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25868Patch KB5073698 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8276Patch KB5073723 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6491Patch KB5073455 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32230Patch KB5073379 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2092Patch KB5073450 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6809Patch KB5073724 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4648Patch KB5073457 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6809Patch KB5073724
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20805?
CVE-2026-20805 has been rated as a high severity vulnerability due to the potential for unauthorized disclosure of sensitive information.
How do I fix CVE-2026-20805?
To mitigate CVE-2026-20805, ensure that you apply the relevant security updates from Microsoft for your affected products.
What products are impacted by CVE-2026-20805?
CVE-2026-20805 affects various Microsoft Windows products including Windows Server 2012, Windows 10, Windows Server 2016, and multiple versions of Windows 11.
Can CVE-2026-20805 be exploited remotely?
CVE-2026-20805 requires local access for exploitation, meaning that an attacker must have physical or local access to the affected machine.
What types of attacks can CVE-2026-20805 facilitate?
CVE-2026-20805 can facilitate attacks that exploit the information disclosure to gain unauthorized access to sensitive user information.