Windows info-disclosure 0-day bug gets a fix as CISA sounds alarm
ID: 3cc5d058-cb9a-5244-adba-b3d5caab300a
STIX ID: report--3cc5d058-cb9a-5244-adba-b3d5caab300a
Feed Name: The Register (Security)
Microsoft disclosed CVE-2026-20805, a medium-severity (CVSS 5.5) Windows zero‑day that can leak a memory address from a remote ALPC port and enable ASLR bypass; the flaw has been observed under attack and was added by CISA to its Known Exploited Vulnerabilities catalog, with a federal mitigation deadline. The January patch bundle also includes other publicly known issues and multiple Office use‑after‑free bugs, with guidance emphasizing rapid patching as the primary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
