CVE-2026-20854Use After Free in Microsoft Windows 11 Version 24h2

CWE-416Use After Free5 documents5 sources
Severity
7.5HIGHNVD
EPSS
0.1%
top 78.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages6 packages

NVDmicrosoft/windows< 10.0.26100.32230
NVDmicrosoft/windows_11_24h2< 10.0.26100.7623
NVDmicrosoft/windows_11_25h2< 10.0.26200.7623
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.32230
CVEListV5microsoft/windows_11_version_24h210.0.26100.010.0.26100.7623

🔴Vulnerability Details

2
GHSA
GHSA-7g73-j999-7mq6: Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network2026-01-13
CVEList
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability2026-01-13

📋Vendor Advisories

1
Microsoft
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability2026-01-13

🕵️Threat Intelligence

1
Wiz
CVE-2026-20854 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-20854 — Use After Free in Microsoft | cvebase