Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026011902012929 | Publication Time | 2026/01/19 14:52 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/01/19 14:52 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】ISA Adds Two Known Exploited Vulnerabilities to the KEV Catalog (2026/01/12–2026/01/18) |
|||
|
[Content] 【Whether Ransomware Exploitation Occurred: Unknown】 A path traversal vulnerability exists in Gogs. Improper handling of symbolic links in the PutContents API may lead to remote code execution. 【CVE-2026-20805】Microsoft Windows Information Disclosure Vulnerability (CVSS v3.1: 5.5) 【Whether Ransomware Exploitation Occurred: Unknown】 An information disclosure vulnerability exists in Microsoft Windows Desktop Window Manager. This vulnerability allows an authenticated attacker to disclose information locally. |
|||
|
[Affected Platform] 【CVE-2026-20805】Please refer to the affected versions listed by the official source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20805 |
|||
|
[Recommended Actions] 【CVE-2026-20805】The vendor has released a patch for this vulnerability. Please update to the relevant versions: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20805 |
|||
| [Reference] | |||