Vulnerabilities
Vulnerable Software
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.033
Published
2026-01-13
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.004
Published
2026-01-13
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
CVSS Score
4.6
EPSS Score
0.007
Published
2026-01-13
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.
CVSS Score
4.6
EPSS Score
0.006
Published
2026-01-13
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.003
Published
2026-01-13
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.025
Published
2026-01-13
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.
CVSS Score
6.2
EPSS Score
0.007
Published
2026-01-13
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
CVSS Score
5.5
EPSS Score
0.009
Published
2026-01-13
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.024
Published
2026-01-13
CVE-2026-20805
Known exploited
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.05
Published
2026-01-13


Contact Us

Shodan ® - All rights reserved