CVE-2026-20838

G

eneration of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*

History

15 Jan 2026, 15:15

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20838 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20838 - Vendor Advisory
First Time Microsoft windows 11 23h2
Microsoft windows Server 2022 23h2
Microsoft windows 11 24h2
Microsoft windows Server 2022
Microsoft windows 11 25h2
Microsoft
Microsoft windows Server 2025

13 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 18:16

Updated : 2026-01-15 15:15


NVD link : CVE-2026-20838

Mitre link : CVE-2026-20838

CVE.ORG link : CVE-2026-20838


JSON object : View

CWE
CWE-209

Generation of Error Message Containing Sensitive Information