CVE-2026-20875

Severity
7.5HIGH
EPSS
0.1%
top 76.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages31 packages

CVEListV5microsoft/windows_server_2008_service_pack_26.0.6003.06.0.6003.23717
CVEListV5microsoft/windows_server_2008_r2_service_pack_16.1.7601.06.1.7601.28117
NVDmicrosoft/windows< 10.0.14393.8783+5

🔴Vulnerability Details

2
CVEList
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability2026-01-13
GHSA
GHSA-hjhf-9j6x-5777: Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network2026-01-13

📋Vendor Advisories

1
Microsoft
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability2026-01-13

🕵️Threat Intelligence

1
Wiz
CVE-2026-20875 Impact, Exploitability, and Mitigation Steps | Wiz