cbcvebase.
CVE-2026-20838
published 2026-01-13

CVE-2026-20838: Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

Affected

21 ranges
VendorProductVersion rangeFixed in
microsoftwindows_11_23h2< 10.0.22631.649110.0.22631.6491
microsoftwindows_11_24h2< 10.0.26100.762310.0.26100.7623
microsoftwindows_11_25h2< 10.0.26200.762310.0.26200.7623
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.649110.0.22631.6491
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.649110.0.22631.6491
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.762310.0.26100.7623
microsoftwindows_11_version_25h2>= 10.0.26200.0 < 10.0.26200.762310.0.26200.7623
microsoftwindows_server_2022< 10.0.20348.464810.0.20348.4648
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.464810.0.20348.4648
microsoftwindows_server_2022_23h2< 10.0.25398.209210.0.25398.2092
microsoftwindows_server_2025< 10.0.26100.3223010.0.26100.32230
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.3223010.0.26100.32230
msrcwindows_11_version_23h2_for_arm64-based_systems
msrcwindows_11_version_23h2_for_x64-based_systems
msrcwindows_11_version_24h2_for_arm64-based_systems
msrcwindows_11_version_24h2_for_x64-based_systems
msrcwindows_11_version_25h2_for_arm64-based_systems
msrcwindows_11_version_25h2_for_x64-based_systems
msrcwindows_server_2022
msrcwindows_server_2022_23h2_edition
msrcwindows_server_2025