#VU121230 Information disclosure in Windows and Windows Server - CVE-2026-20805
Published: January 13, 2026
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the Desktop Windows Manager. A local user can gain access to a section address from a remote ALPC port, which is user-mode memory.
Note, the vulnerability is being actively exploited in the wild.