Microsoft Patch Tuesday Analysis – January 2026
Executive Summary
On Tuesday, January 13, 2026, Microsoft released its monthly security patch, addressing 112 vulnerabilities in its products.
By severity:
- Remote Code Execution - 22;
- Elevation of Privilege - 55;
- Tampering - 3;
- Information Disclosure - 22;
- Security Feature Bypass - 3;
- Spoofing - 5;
- Denial of Service - 2.
Exploited (Zero-Days) and Publicly Disclosed Vulnerabilities
Particular attention should be paid to the following 2 vulnerabilities. Their fixes are high-priority:
- CVE-2026-20805 (CVSS 5.5; Information Disclosure) - Desktop Window Manager Information Disclosure Vulnerability (Information Disclosure). A vulnerability in the Desktop Window Manager (DWM) allows an authenticated local attacker to gain access to the contents of user mode memory. The exploitation leads to the disclosure of the ALPC (Advanced Local Procedure Call) port address.
- CVE-2026-21265 (CVSS 6.4; Security Feature Bypass) - Secure Boot Certificate Expiration Security Feature Bypass Vulnerability (Security Feature Bypass). A vulnerability in the Secure Boot protection mechanism, related to the upcoming expiration of Microsoft Key Exchange (KEK) and Device Builder (DB) certificates stored in UEFI, allows an attacker with high privileges to bypass the secure boot process. The problem is caused by the updating mechanism of these certificates, which relies on components that may not work correctly, breaking the chain of trust. Successful exploitation allows an attacker to bypass the secure boot process.
General Overview and Trends
The first Patch Tuesday of 2026 sets a high bar for the year: Microsoft released fixes for 112 vulnerabilities, which exceeds the number of fixes released in December (57) and November (63). This release sets a high tempo for information security specialists. The key trends of this month:
- Attacks on the graphics subsystem and boot process: Two critical vulnerabilities are in the spotlight. The vulnerability in the Desktop Window Manager (DWM) has already been exploited by attackers to read memory, which is often the first step in an exploit chain. In parallel, the publicly disclosed vulnerability in Secure Boot, related to the expiration of certificates, poses a threat to the fundamental trust in the OS boot process, requiring a careful UEFI update.
- Elevation of Privilege (EoP): More than half of all fixes (55 out of 112) are related to Elevation of Privilege vulnerabilities. This continues the trend seen at the end of 2025. The vulnerabilities affect all key system components: from drivers and the Common Log File System to the Windows Management Services.
- Critical RCE in corporate software: A significantative block of fixes (22 RCE) is aimed at addressing vulnerabilities in remote code execution in Microsoft SharePoint and Office. Given the popularity of SharePoint as a corporate data repository, the presence of multiple RCE makes these servers a priority target for attackers and shadow IT.
- Attention to peripherals and device drivers: A large number of fixes affect device drivers, graphics components, and services for connected devices. Low-level errors in these components are often used to bypass security mechanisms and OS defenses.
Full List of Vulnerabilities
This table contains all the vulnerabilities that were fixed this month.
| CVE | Title | Type | CVSS | Severity | Exploited | Publicly Disclosed |
|---|---|---|---|---|---|---|
| CVE-2026-21265 | Secure Boot Certificate Expiration Security Feature Bypass Vulnerability | Security Feature Bypass | 6.4 | Security Feature Bypass | No | Yes |
| CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | Yes | No |
| CVE-2026-20868 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Remote Code Execution | No | No |
| CVE-2026-20947 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Remote Code Execution | No | No |
| CVE-2026-20963 | Microsoft SharePoint Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Remote Code Execution | No | No |
| CVE-2026-20944 | Microsoft Word Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Remote Code Execution | No | No |
| CVE-2026-20952 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Remote Code Execution | No | No |
| CVE-2026-20953 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Remote Code Execution | No | No |
| CVE-2026-20856 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Remote Code Execution | No | No |
| CVE-2026-20931 | Windows Telephony Service Elevation of Privilege Vulnerability | Elevation of Privilege | 8.0 | Elevation of Privilege | No | No |
| CVE-2026-20809 | Windows Kernel Memory Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20810 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20811 | Win32k Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20816 | Windows Installer Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20817 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20820 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20822 | Windows Graphics Component Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20826 | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20831 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20832 | Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20837 | Windows Media Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Remote Code Execution | No | No |
| CVE-2026-20840 | Windows NTFS Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Remote Code Execution | No | No |
| CVE-2026-20843 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20857 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20858 | Windows Management Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20859 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20860 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20861 | Windows Management Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20864 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20865 | Windows Management Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20866 | Windows Management Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20867 | Windows Management Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20870 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20871 | Desktop Windows Manager Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20873 | Windows Management Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20874 | Windows Management Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20877 | Windows Management Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20918 | Windows Management Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20920 | Win32k Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20922 | Windows NTFS Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Remote Code Execution | No | No |
| CVE-2026-20923 | Windows Management Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20924 | Windows Management Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20938 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20940 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20941 | Host Process for Windows Tasks Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20946 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Remote Code Execution | No | No |
| CVE-2026-20948 | Microsoft Word Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Remote Code Execution | No | No |
| CVE-2026-20949 | Microsoft Excel Security Feature Bypass Vulnerability | Security Feature Bypass | 7.8 | Security Feature Bypass | No | No |
| CVE-2026-20950 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Remote Code Execution | No | No |
| CVE-2026-20951 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Remote Code Execution | No | No |
| CVE-2026-20955 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Remote Code Execution | No | No |
| CVE-2026-20956 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Remote Code Execution | No | No |
| CVE-2026-20957 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Remote Code Execution | No | No |
| CVE-2026-21224 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Elevation of Privilege | No | No |
| CVE-2026-20804 | Windows Hello Tampering Vulnerability | Tampering | 7.7 | Tampering | No | No |
| CVE-2026-20852 | Windows Hello Tampering Vulnerability | Tampering | 7.7 | Tampering | No | No |
| CVE-2026-0386 | Windows Deployment Services Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Remote Code Execution | No | No |
| CVE-2026-20848 | Windows SMB Server Elevation of Privilege Vulnerability | Elevation of Privilege | 7.5 | Elevation of Privilege | No | No |
| CVE-2026-20849 | Windows Kerberos Elevation of Privilege Vulnerability | Elevation of Privilege | 7.5 | Elevation of Privilege | No | No |
| CVE-2026-20854 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Remote Code Execution | No | No |
| CVE-2026-20875 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | Denial of Service | 7.5 | Denial of Service | No | No |
| CVE-2026-20919 | Windows SMB Server Elevation of Privilege Vulnerability | Elevation of Privilege | 7.5 | Elevation of Privilege | No | No |
| CVE-2026-20921 | Windows SMB Server Elevation of Privilege Vulnerability | Elevation of Privilege | 7.5 | Elevation of Privilege | No | No |
| CVE-2026-20926 | Windows SMB Server Elevation of Privilege Vulnerability | Elevation of Privilege | 7.5 | Elevation of Privilege | No | No |
| CVE-2026-20929 | Windows HTTP.sys Elevation of Privilege Vulnerability | Elevation of Privilege | 7.5 | Elevation of Privilege | No | No |
| CVE-2026-20934 | Windows SMB Server Elevation of Privilege Vulnerability | Elevation of Privilege | 7.5 | Elevation of Privilege | No | No |
| CVE-2026-20965 | Windows Admin Center Elevation of Privilege Vulnerability | Elevation of Privilege | 7.5 | Elevation of Privilege | No | No |
| CVE-2026-21226 | Azure Core shared client library for Python Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Remote Code Execution | No | No |
| CVE-2026-20844 | Windows Clipboard Server Elevation of Privilege Vulnerability | Elevation of Privilege | 7.4 | Elevation of Privilege | No | No |
| CVE-2026-20853 | Windows WalletService Elevation of Privilege Vulnerability | Elevation of Privilege | 7.4 | Elevation of Privilege | No | No |
| CVE-2026-20803 | Microsoft SQL Server Elevation of Privilege Vulnerability | Elevation of Privilege | 7.2 | Elevation of Privilege | No | No |
| CVE-2026-20808 | Windows File Explorer Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Elevation of Privilege | No | No |
| CVE-2026-20814 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Elevation of Privilege | No | No |
| CVE-2026-20815 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Elevation of Privilege | No | No |
| CVE-2026-20830 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Elevation of Privilege | No | No |
| CVE-2026-20836 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Elevation of Privilege | No | No |
| CVE-2026-20842 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Elevation of Privilege | No | No |
| CVE-2026-20863 | Win32k Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Elevation of Privilege | No | No |
| CVE-2026-20869 | Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Elevation of Privilege | No | No |
| CVE-2026-20943 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | Remote Code Execution | 7.0 | Remote Code Execution | No | No |
| CVE-2026-21219 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | Remote Code Execution | 7.0 | Remote Code Execution | No | No |
| CVE-2026-21221 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Elevation of Privilege | No | No |
| CVE-2026-20876 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | Elevation of Privilege | 6.7 | Elevation of Privilege | No | No |
| CVE-2026-20812 | LDAP Tampering Vulnerability | Tampering | 6.5 | Tampering | No | No |
| CVE-2026-20847 | Microsoft Windows File Explorer Spoofing Vulnerability | Spoofing | 6.5 | Spoofing | No | No |
| CVE-2026-20872 | NTLM Hash Disclosure Spoofing Vulnerability | Spoofing | 6.5 | Spoofing | No | No |
| CVE-2026-20925 | NTLM Hash Disclosure Spoofing Vulnerability | Spoofing | 6.5 | Spoofing | No | No |
| CVE-2026-20818 | Windows Kernel Information Disclosure Vulnerability | Information Disclosure | 6.2 | Information Disclosure | No | No |
| CVE-2026-20821 | Remote Procedure Call Information Disclosure Vulnerability | Information Disclosure | 6.2 | Information Disclosure | No | No |
| CVE-2026-20851 | Capability Access Management Service (camsvc) Information Disclosure Vulnerability | Information Disclosure | 6.2 | Information Disclosure | No | No |
| CVE-2026-20935 | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | Information Disclosure | 6.2 | Information Disclosure | No | No |
| CVE-2026-20819 | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20823 | Windows File Explorer Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20824 | Windows Remote Assistance Security Feature Bypass Vulnerability | Security Feature Bypass | 5.5 | Security Feature Bypass | No | No |
| CVE-2026-20827 | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20829 | TPM Trustlet Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20833 | Windows Kerberos Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20835 | Capability Access Management Service (camsvc) Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20838 | Windows Kernel Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20839 | Windows Client-Side Caching (CSC) Service Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20862 | Windows Management Services Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20932 | Windows File Explorer Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20937 | Windows File Explorer Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20939 | Windows File Explorer Information Disclosure Vulnerability | Information Disclosure | 5.5 | Information Disclosure | No | No |
| CVE-2026-20958 | Microsoft SharePoint Information Disclosure Vulnerability | Information Disclosure | 5.4 | Information Disclosure | No | No |
| CVE-2026-20927 | Windows SMB Server Denial of Service Vulnerability | Denial of Service | 5.3 | Denial of Service | No | No |
| CVE-2026-20828 | Windows rndismp6.sys Information Disclosure Vulnerability | Information Disclosure | 4.6 | Information Disclosure | No | No |
| CVE-2026-20834 | Windows Spoofing Vulnerability | Spoofing | 4.6 | Spoofing | No | No |
| CVE-2026-20959 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 4.6 | Spoofing | No | No |
| CVE-2026-20825 | Windows Hyper-V Information Disclosure Vulnerability | Information Disclosure | 4.4 | Information Disclosure | No | No |
| CVE-2026-20962 | Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability | Information Disclosure | 4.4 | Information Disclosure | No | No |
| CVE-2026-20936 | Windows NDIS Information Disclosure Vulnerability | Information Disclosure | 4.3 | Information Disclosure | No | No |
Retrospective Analysis of Vulnerabilities
- CVE-2025-62454 — Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability (Elevation of Privilege). The vulnerability is a heap-based buffer overflow in the cldflt.sys driver, which is responsible for working with cloud files (for example, OneDrive). The problem occurs in the memcpy function due to incorrect validation of input data when processing a special control code (FSCTL 0x903bc) related to HSM. Successful exploitation allows a local attacker to execute arbitrary code in the context of the SYSTEM and elevate privileges to the SYSTEM level. Available PoC demonstrates the ability to initiate a system crash (BSOD) through attribute manipulation. The vulnerability was fixed in December 2025.
- CVE-2025-62470 - Windows Common Log File System Driver Elevation of Privilege Vulnerability (Elevation of Privilege). The vulnerability is a heap-based buffer overflow in the CLFS.sys driver, which allows a local attacker to elevate privileges to the SYSTEM level. The error occurs in the ClfsEncodeBlock function due to insufficient validation of the TotalSectorCount and ValidSectorCount fields in the CLFS_LOG_BLOCK_HEADER structure. Available PoC demonstrates the ability to initiate a system crash (BSOD) through a specially crafted IOCTL request, which confirms non-secure memory access. The vulnerability was fixed in December 2025.
- CVE-2025-64669 — Windows Admin Center Elevation of Privilege Vulnerability (Elevation of Privilege). The vulnerability is a local elevation of privileges, discovered by Cymulate Research Lab. The root cause is insecure access rights to the C:\ProgramData\WindowsAdminCenter directory, which is accessible for writing by a standard user. This allows an attacker to elevate privileges to the SYSTEM level using a DLL hijacking attack during the update process (Updater DLL Hijacking) or using PowerShell scripts during the uninstallation of extensions. Detailed technical analysis of the exploitation methods is available. The vulnerability was fixed in December 2025.
Conclusion
The January 2026 patch is a significant and critical update, and IT departments should prioritize the installation of the patches for the following vulnerabilities:
- Actively exploit CVE-2026-20805 (DWM, Information Disclosure), to prevent the use of this vulnerability in combination with other exploits.
- Publicly disclose CVE-2026-21265 (Secure Boot, Security Feature Bypass), as the expiration of certificates creates a window of opportunity for attackers to bypass the Secure Boot security feature.
- Critical RCE vulnerabilities in SharePoint (CVE-2026-20947, CVE-2026-20963) and Office pose a maximum threat to the integrity of corporate data.
Additionally, attention should be drawn to the Retrospective Analysis of Vulnerabilities section. Publication of PoC exploits for vulnerabilities in the Cloud Files and Common Log File System drivers, as well as for Windows Admin Center, make them trivial for exploitation if the December patches are not installed. If the December patches have not been installed, the risk of a system compromise through these vectors becomes extremely high.