#VU121253 Double free in Windows and Windows Server - CVE-2026-20832
Published: January 13, 2026
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in Windows Remote Procedure Call Interface Definition Language (IDL). A local user can pass specially crafted data to the application, trigger double free error and gain elevated privileges on the target system.