2026年1月14日星期三

Microsoft Monthly Security Update (January 2026)

Microsoft Monthly Security Update (January 2026)

Release Date: 14 Jan 2026

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
WindowsMedium Risk Medium RiskInformation Disclosure
Security Restriction Bypass
Remote Code Execution
Data Manipulation
Elevation of Privilege
Spoofing
Denial of Service

CVE-2026-20805 is being exploited in the wild. This vulnerability exist in Desktop Window Manager. Successful exploitation of this vulnerability could allow an authorized attacker to disclose information locally.  Hence, the risk level of this vulnerability is rated as Medium Risk.

 

CVE-2026-21265 is considered publicly disclosed. This vulnerability exist in the Windows Secure Boot. Microsoft certificates are stored in the Unified Extensible Firmware Interface Key Enrollment Key and DB. These certificates need to be updated to ensure Secure Boot functionality remains and to prevent future issues from arising. 

Extended Security Updates (ESU)Medium Risk Medium RiskSecurity Restriction Bypass
Remote Code Execution
Information Disclosure
Elevation of Privilege
Spoofing
Denial of Service

CVE-2026-20805 is being exploited in the wild. This vulnerability exist in Desktop Window Manager. Successful exploitation of this vulnerability could allow an authorized attacker to disclose information locally.  Hence, the risk level of this vulnerability is rated as Medium Risk.

SQL ServerMedium Risk Medium RiskElevation of Privilege 
AzureMedium Risk Medium RiskElevation of Privilege
Remote Code Execution
 
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution
Spoofing
Security Restriction Bypass
Information Disclosure
 
Developer ToolsMedium Risk Medium RiskRemote Code Execution 
BrowserLow Risk Low Risk  
Open Source SoftwareLow Risk Low Risk  
MarinerLow Risk Low Risk  

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 6

Number of 'Low Risk' product(s): 3

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Elevation of Privilege
  • Spoofing
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

  • Windows
  • Extended Security Updates (ESU)
  • SQL Server
  • Azure
  • Microsoft Office
  • Developer Tools
  • Browser
  • Open Source Software
  • Mariner

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

F5 產品多個漏洞

F5 產品多個漏洞 發佈日期: 2026年05月15日 風險: 中度風險 類型: 操作系統 - Network 於 F5 產品發現多個漏洞。遠端...