CVE-2026-20838Information Exposure via Error Message in Microsoft Windows 11 Version 22h3

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 82.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages10 packages

NVDmicrosoft/windows< 10.0.20348.4648+2
NVDmicrosoft/windows_11_23h2< 10.0.22631.6491
NVDmicrosoft/windows_11_24h2< 10.0.26100.7623
NVDmicrosoft/windows_11_25h2< 10.0.26200.7623
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.4648

🔴Vulnerability Details

2
CVEList
Windows Kernel Information Disclosure Vulnerability2026-01-13
GHSA
GHSA-6j3g-2jh3-q8rg: Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally2026-01-13

📋Vendor Advisories

1
Microsoft
Windows Kernel Information Disclosure Vulnerability2026-01-13

🕵️Threat Intelligence

1
Wiz
CVE-2026-20838 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-20838 — Information Exposure via Error Message | cvebase