CVE-2026-20805

MEDIUM KEV

Desktop Windows Manager - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-20805 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 13, 2026. EIP tracks 6 public exploits from researchers including fevar54, Uzair-Baig0900, XZ1r0.

AI-analyzed exploit summary This repository provides a writeup and conceptual proof-of-concept for CVE-2026-20805, an information disclosure vulnerability in Microsoft Windows Desktop Windows Manager (dwm.exe). It describes a local attack to leak memory addresses via ALPC ports but does not include actual exploit code.

Description

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Exploits (6)

nomisec WRITEUP 7 stars
by fevar54 · poc
https://github.com/fevar54/CVE-2026-20805-POC

This repository provides a writeup and conceptual proof-of-concept for CVE-2026-20805, an information disclosure vulnerability in Microsoft Windows Desktop Windows Manager (dwm.exe). It describes a local attack to leak memory addresses via ALPC ports but does not include actual exploit code.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Windows (Desktop Windows Manager - dwm.exe)
Auth required
Prerequisites: Local access to the target system · Low-privileged user account
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by Uzair-Baig0900 · infoleak
https://github.com/Uzair-Baig0900/CVE-2026-20805-PoC

This PoC demonstrates an information disclosure vulnerability in Microsoft Desktop Window Manager (dwm.exe) by monitoring process handles and memory regions for anomalies. It uses Windows API calls to enumerate system handles and inspects dwm.exe for potential leaks.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Desktop Window Manager (dwm.exe)
Auth required
Prerequisites: Windows OS · Administrative privileges · Python environment
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github SCANNER
by XZ1r0 · pythonpoc
https://github.com/XZ1r0/cve-2026-poc-collection/tree/main/windows/CVE-2026-20805-POC

The repository contains a Python script designed to monitor handles and memory regions of the Desktop Windows Manager (dwm.exe) process for anomalies indicative of an information disclosure vulnerability (CVE-2026-20805). It does not exploit the vulnerability but provides a framework for detecting potential leaks.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Windows Desktop Windows Manager (dwm.exe)
Auth required
Prerequisites: local access to the target system · elevated privileges for handle enumeration
devstral-2 · analyzed May 21, 2026 Full analysis →
nomisec WORKING POC
by SimoesCTT · poc
https://github.com/SimoesCTT/SCTT-2026-33-0002-DWM-Visual-Field-Singularity

This PoC exploits a theoretical vulnerability in Desktop Window Manager (dwm.exe) by inducing a phase transition via visual resonance to achieve local privilege escalation (LPE) to SYSTEM. It leverages temporal and spatial resonance patterns to manipulate the DWM composition buffer.

Classification
Working Poc 85%
Attack Type
Lpe
Complexity
Complex
Reliability
Theoretical
Target: Desktop Window Manager (dwm.exe) / Windows Graphics Component
No auth needed
Prerequisites: Local access to a vulnerable Windows system · Desktop Window Manager (dwm.exe) running
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by SimoesCTT · poc
https://github.com/SimoesCTT/-SCTT-2026-33-0002-DWM-Visual-Field-Singularity

The repository contains a Python-based exploit for CVE-2026-20805, targeting a theoretical vulnerability in the Desktop Window Manager (dwm.exe) via NFS protocol manipulation. It leverages temporal resonance and fluid dynamics principles to achieve local privilege escalation (LPE) to SYSTEM.

Classification
Working Poc 80%
Attack Type
Lpe
Complexity
Complex
Reliability
Theoretical
Target: Desktop Window Manager (dwm.exe) / Windows Graphics Component
No auth needed
Prerequisites: Local access to a vulnerable Windows system · NFS protocol accessibility
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by mrk336 · poc
https://github.com/mrk336/Inside-CVE-2026-20805-How-a-Windows-DWM-Flaw-Exposed-Sensitive-Data

The repository provides a detailed writeup and conceptual PowerShell script for CVE-2026-20805, a Windows DWM information disclosure flaw. It includes technical analysis, detection rules, and mitigation strategies but lacks a functional exploit.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Theoretical
Target: Windows Desktop Window Manager (DWM) on Windows 10.0.19041 and derivatives
No auth needed
Prerequisites: Local access to the target system · Low privileges
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 5.5
EPSS 0.0206
EPSS Percentile 84.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2026-01-13
VulnCheck KEV 2026-01-13
ENISA EUVD EUVD-2026-2073
CWE
CWE-200
Status published
Products (34)
Microsoft/Windows 10 Version 1607 10.0.14393.0 - 10.0.14393.8783
Microsoft/Windows 10 Version 1809 10.0.17763.0 - 10.0.17763.8276
Microsoft/Windows 10 Version 21H2 10.0.19044.0 - 10.0.19044.6809
Microsoft/Windows 10 Version 22H2 10.0.19045.0 - 10.0.19045.6809
Microsoft/Windows 11 version 22H3 10.0.22631.0 - 10.0.22631.6491
Microsoft/Windows 11 Version 23H2 10.0.22631.0 - 10.0.22631.6491
Microsoft/Windows 11 Version 24H2 10.0.26100.0 - 10.0.26100.7623
Microsoft/Windows 11 Version 25H2 10.0.26200.0 - 10.0.26200.7623
Microsoft/Windows Server 2012 6.2.9200.0 - 6.2.9200.25868
Microsoft/Windows Server 2012 (Server Core installation) 6.2.9200.0 - 6.2.9200.25868
... and 24 more
Published Jan 13, 2026
KEV Added Jan 13, 2026
Tracked Since Feb 18, 2026