CVE-2026-20941Disclosure(microsoft / windows_11_24h2)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_24h2
  • windows_11_25h2
  • windows_server_2025

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_11_24h2windows_11_25h2windows_server_2025

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-26: 1Mentions · 2026-03-02: 1PoC Mentioned / Linked · 2026-03-02: 1Technical Details · 2026-02-26: 1Technical Details · 2026-03-02: 102-2603-02
Signal classification1 categories
Disclosure
2100.0%
Referenced assets4 URLs
Full discourse2 posts
  • Crowdfense@crowdfense
    Disclosure

    The following weaponized vulnerabilities have been added to our n-day feed: - CVE-2025-61882: Oracle EBS - RCE - CVE-2026-24423: SmarterMail - RCE - CVE-2026-20941: Host Process - LPE - 0DAY-2026-0001: Visual Studio - Info Disclosure https://www.crowdfense.com/n-day-feed/

    Post summary

    The feed announces four new CVEs and a zero‑day, specifying only the affected product and vulnerability type, with no further technical or mitigation details.

    06029102.0K
    2.9K followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    #exploit 1⃣ Total Recall - Retracing Your Steps Back to NT AUTHORITY\SYSTEM https://www.mdsec.co.uk/2026/02/total-recall-retracing-your-steps-back-to-nt-authoritysystem // Researchers uncovered a Windows 11 privilege escalation flaw exploiting WNF state names and scheduled tasks to achieve SYSTEM-level code execution (CVE-2026-20941) 2⃣ Bypassing Apache FOP Postscript Escaping to reach GhostScript https://offsec.almond.consulting/bypassing-apache-fop-escaping-to-reach-ghostscript.html // Vulnerability in Apache FOP's PostScript generation allows crafted input to execute arbitrary code and escape sandbox via PostScript injection 3⃣ Cred Relay Issue #2 https://www.credrelay.com/p/cred-relay-issue-2 // Privilege escalation in ASUS PTP driver due to insecure device creation lacking SDDL security descriptors

    Post summary

    The text announces three newly discovered privilege escalation and code execution vulnerabilities, provides technical details and links to PoC resources, but does not mention active exploitation or patches.

    01093562
    3.1K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2025---

Explore more