Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Microsoft
CVE-2026-20840 CVSS 7.8
2026-01-13 08:00 UTC · 2026-01-13 05:00 -03
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.