CVE-2026-20941 is a local privilege escalation vulnerability affecting Microsoft Windows 11 (24H2, 25H2) and Windows Server 2025, stemming from improper link resolution before file access in the Host Process for Windows Tasks. With a CVSS score of 7.8 (High), an authorized attacker can exploit this flaw with low attack complexity to achieve high confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.26100.7623CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.26100.7623CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* | ||
< 10.0.26200.7623CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.26200.7623CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:* | ||
< 10.0.26100.32230CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.