⚠️ CISA Known Exploited Vulnerability
Active ThreatThis vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.
CVE-2026-20805
Medium CISA KEVVulnerability Description
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Known Affected Software
195 configuration(s) from 1 vendor(s)
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2029:*:*:*:datacenter:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2728:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.887:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7434:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2061:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.3887:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1547:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2788:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2227:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.770:*:*:*:datacenter:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.4161:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.350:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.617:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7919:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1726:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3930:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5011:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.3287:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.469:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5371:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1607:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.4974:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.4046:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.405:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.4737:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.709:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.4651:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2655:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2522:*:*:*:datacenter:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.4291:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3328:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.4412:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.4131:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.6893:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.8027:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2849:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3932:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3803:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3516:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2031:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.524:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2201:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1668:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5737:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2333:*:*:*:datacenter:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.768:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2673:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5608:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.6414:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2452:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7792:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7783:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.3046:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.473:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.6293:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.6575:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.587:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2402:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1602:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1311:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.261:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19041.3920:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2965:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2604:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2486:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2846:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.6532:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1850:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3630:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.5936:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1724:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2966:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.5458:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3148:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2803:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2546:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2565:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.4294:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.859:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.6332:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.5576:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5854:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7136:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3271:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1070:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1249:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1251:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.4297:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1366:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.4894:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.4170:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2183:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.707:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2913:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2762:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2928:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3086:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.6189:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.6054:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.6321:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7009:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1903:*:*:*:datacenter:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2364:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2114:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1787:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.803:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2700:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.4052:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.558:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2130:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3207:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3745:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1131:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.230:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.4171:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.5820:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3807:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1129:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3208:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.4106:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2237:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.380:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.407:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.681:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2340:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1906:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3692:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.946:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.4499:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2461:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.5122:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7314:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2159:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7678:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.4252:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5247:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1540:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19044.2486:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.6216:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.3406:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.4405:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2582:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.5329:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.1999:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.643:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.6456:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7922:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.3770:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3693:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2113:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.6659:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5965:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5131:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.288:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3270:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.320:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.6093:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1194:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19044.3324:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.3532:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3570:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5487:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.5696:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7558:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1970:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.4346:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3393:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2322:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.825:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.3650:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3453:*:*:*:-:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.4645:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2366:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.4851:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3324:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2251:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3448:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19042.2486:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1006:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2458:*:*:*:datacenter:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1368:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.1487:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3989:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.2311:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.740:*:*:*:azure:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2300:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3087:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3031:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.3165:*:*:*:standard:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.3155:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.4010:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.4780:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.502:*:*:*:azure:*:x64:*
Severity Details
CISA KEV Status
Listed in CISA's Known Exploited Vulnerabilities catalog
Weakness Type (CWE)
Exposure of Sensitive Information to an Unauthorized Actor
- Description
- The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- Exploit Likelihood
- High
- Typical Severity
- Medium
- Abstraction Level
- Class
Key Information
- Published Date
- January 13, 2026
External Resources
Related News Articles
Latest news and updates about CVE-2026-20805
