{"id":"CVE-2026-20935","details":"Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.","modified":"2026-03-13T03:55:53.306728Z","published":"2026-01-13T18:16:20.500Z","references":[{"type":"ADVISORY","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20935"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"10.0.22631.6491"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.22631.6491"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.26100.7623"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.26100.7623"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.26200.7623"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.26200.7623"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-20935.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}