CVE-2026-20821: Remote Procedure Call Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.
Other sources
Remote Procedure Call Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.28117Patch KB5073699 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25868Patch KB5073698 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22968Patch KB5073696 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8783Patch KB5073722 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23717Patch KB5073700 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2092Patch KB5073450 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6491Patch KB5073455 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32230Patch KB5073379 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6809Patch KB5073724 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6809Patch KB5073724 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4648Patch KB5073457 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8276Patch KB5073723
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20821?
CVE-2026-20821 has been classified as a significant information disclosure vulnerability.
How do I fix CVE-2026-20821?
To fix CVE-2026-20821, apply the relevant security updates provided by Microsoft for your affected Windows operating system.
What systems are affected by CVE-2026-20821?
CVE-2026-20821 impacts various versions of Windows Server, including 2008, 2008 R2, 2012, and 2016, as well as Windows 10 and Windows 11.
What type of vulnerability is CVE-2026-20821?
CVE-2026-20821 is classified specifically as a Remote Procedure Call Information Disclosure Vulnerability.
Can CVE-2026-20821 be exploited remotely?
Yes, CVE-2026-20821 can be exploited by unauthorized attackers to disclose sensitive information locally.