Microsoft January Security Update Addresses Critical Vulnerabilities in Multiple Products
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
On January 14, Microsoft issued its January Security Update, which fixed 112 vulnerabilities across widely used products such as Windows, Microsoft Office, Microsoft SQL Server, and Azure. This update includes eight critical vulnerabilities and 104 important ones, highlighting the urgency for users to apply the patches. Notably, the Desktop Window Manager Information Disclosure Vulnerability (CVE-2026-20805) has already been exploited, emphasizing the need for immediate action.
Among the critical vulnerabilities, the Microsoft Office Remote Code Execution Vulnerability (CVE-2026-20952/CVE-2026-20953) poses a significant risk, allowing unauthenticated attackers to execute arbitrary code by tricking users into opening malicious documents. This vulnerability has a CVSS score of 8.4, indicating its severity. Similarly, the Microsoft Excel Remote Code Execution Vulnerability (CVE-2026-20955/CVE-2026-20957) also allows attackers to execute code through malicious files, with a CVSS score of 7.8.
Other critical vulnerabilities include the Microsoft Word Remote Code Execution Vulnerability (CVE-2026-20944) and the Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability (CVE-2026-20854), both of which can lead to severe security breaches. The LSASS vulnerability has a CVSS score of 7.5, indicating a high risk for users.
Key Vulnerabilities and Their Impact
The vulnerabilities addressed in this update affect a wide range of product versions. For example, the Desktop Window Manager Information Disclosure Vulnerability affects multiple Windows versions, including Windows 10 and Windows 11. Microsoft Office vulnerabilities impact various editions, including Microsoft Office 2016, 2019, and Microsoft 365 Apps for Enterprise.
Given the critical nature of these vulnerabilities, users are strongly advised to install the security patches as soon as possible. Failure to do so could leave systems exposed to exploitation, leading to potential data breaches or unauthorized access.
- Desktop Window Manager Information Disclosure Vulnerability (CVE-2026-20805): An information disclosure vulnerability that allows attackers to obtain sensitive information.
- Microsoft Office Remote Code Execution Vulnerability (CVE-2026-20952/CVE-2026-20953): A vulnerability that enables attackers to execute arbitrary code through malicious documents.
- Microsoft Excel Remote Code Execution Vulnerability (CVE-2026-20955/CVE-2026-20957): Allows attackers to execute code by tricking users into opening malicious files.
- Microsoft Word Remote Code Execution Vulnerability (CVE-2026-20944): A vulnerability that can execute arbitrary code when users open malicious files.
- Windows LSASS Remote Code Execution Vulnerability (CVE-2026-20854): A vulnerability that allows attackers to execute arbitrary code by modifying directory attributes.
- Windows NTFS Remote Code Execution Vulnerability (CVE-2026-20840): Allows authenticated attackers to execute arbitrary code locally.
- Windows Graphics Component Privilege Escalation Vulnerability (CVE-2026-20822): A vulnerability that allows attackers to elevate privileges to SYSTEM.
- Windows VBS Enclave Privilege Escalation Vulnerability (CVE-2026-20876): Enables attackers to elevate privileges to SYSTEM through a buffer overflow issue.
Key Takeaways
- Install the latest Microsoft security patches immediately to protect against critical vulnerabilities.
- Check for updates regularly in Windows Update settings to ensure your system is secure.
- Educate users about the risks of opening unknown documents or links that could exploit vulnerabilities.
- Monitor your systems for unusual activity that may indicate exploitation of these vulnerabilities.
- Review and update security policies to mitigate risks associated with remote code execution vulnerabilities.
Key Terms & Concepts
- CVE: In this article, CVE refers to the Common Vulnerabilities and Exposures system used to identify and catalog vulnerabilities.
- Remote Code Execution: Remote Code Execution is a type of vulnerability that allows an attacker to run arbitrary code on a victim’s machine.
- Privilege Escalation: Privilege Escalation is a security vulnerability that allows an attacker to gain elevated access to resources that are normally protected from an application or user.
- CVSS: CVSS stands for Common Vulnerability Scoring System, which provides a way to capture the principal characteristics of a vulnerability and produce a numerical score.
- Information Disclosure: Information Disclosure is a type of vulnerability that allows unauthorized access to sensitive information.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.