PT-2026-2700 · Microsoft · Windows

Howard Mcgreehan

·

Published

2026-01-13

·

Updated

2026-02-16

·

CVE-2026-20854

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows (affected versions not specified)
Description A use after free condition exists in the Windows Local Security Authority Subsystem Service (LSASS). This allows an authorized attacker to execute code over a network. Remote attackers can execute arbitrary code and affect the system. The vulnerability involves the use of memory after it has been freed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2026-00395
CVE-2026-20854

Affected Products

Windows