CVE-2026-20962

MEDIUM

Product <Version - Info Disclosure

Title source: llm

Description

Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.

Scores

CVSS v3 4.4
EPSS 0.0015
EPSS Percentile 35.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-908
Status published

Affected Products (18)

microsoft/windows_10_1809 < 10.0.17763.8276
microsoft/windows_10_1809 < 10.0.17763.8276
microsoft/windows_10_21h2 < 10.0.19044.6809
microsoft/windows_10_21h2 < 10.0.19044.6809
microsoft/windows_10_21h2 < 10.0.19044.6809
microsoft/windows_10_22h2 < 10.0.19045.6809
microsoft/windows_10_22h2 < 10.0.19045.6809
microsoft/windows_10_22h2 < 10.0.19045.6809
microsoft/windows_11_23h2 < 10.0.22631.6491
microsoft/windows_11_23h2 < 10.0.22631.6491
microsoft/windows_11_24h2 < 10.0.26100.7623
microsoft/windows_11_24h2 < 10.0.26100.7623
microsoft/windows_11_25h2 < 10.0.26200.7623
microsoft/windows_11_25h2 < 10.0.26200.7623
microsoft/windows_server_2019 < 10.0.17763.8276
... and 3 more

Timeline

Published Jan 13, 2026
Tracked Since Feb 18, 2026