CVE-2026-20874 is a high-severity race condition vulnerability in Windows Management Services, affecting various versions of Windows 10, Windows 11, and Windows Server. An authorized local attacker can exploit this flaw to achieve privilege escalation. The vulnerability has a CVSS score of 7.8, indicating a high impact on confidentiality, integrity, and availability, with high attack complexity. While there is no evidence of active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, suggesting a high level of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.8276CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8276CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.6809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.6809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22631.6491CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.