Record summary

CVE-2026-20840 has a selected CVSS score of 7.8 (high).

Description

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 23
ProductSourceVersion rangeStatus
CVE List10.0.14393.0 to < 10.0.14393.8783affected
CVE List10.0.17763.0 to < 10.0.17763.8276affected
CVE List10.0.19044.0 to < 10.0.19044.6809affected
CVE List10.0.19045.0 to < 10.0.19045.6809affected
CVE List10.0.22631.0 to < 10.0.22631.6491affected
CVE List10.0.26100.0 to < 10.0.26100.7623affected
CVE List10.0.26200.0 to < 10.0.26200.7623affected
CVE List6.1.7601.0 to < 6.1.7601.28117affected

Windows Server 2008 R2 Service Pack 1 (Server Core installation)

Browse Microsoft / Windows Server 2008 R2 Service Pack 1 (Server Core installation)
CVE List6.1.7601.0 to < 6.1.7601.28117affected
CVE List6.0.6003.0 to < 6.0.6003.23717affected

Windows Server 2008 Service Pack 2 (Server Core installation)

Browse Microsoft / Windows Server 2008 Service Pack 2 (Server Core installation)
CVE List6.0.6003.0 to < 6.0.6003.23717affected
CVE List6.2.9200.0 to < 6.2.9200.25868affected

References

2