CVE-2026-20806

EUVD-2026-22351
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
Type Confusion
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N