What is CVE-2026-20485?
CVE-2026-20485 is an out of bounds write vulnerability in HFRP due to a missing bounds check. It could allow local escalation of privilege if a malicious actor has already obtained System privilege, with no user interaction required. Apply Patch ID ALPS11049569 to mitigate the issue.
Azərbaycanca: CVE-2026-20485 HFRP-də sərhəd yoxlanışının (bounds check) olmaması səbəbindən yaranan out of bounds write zəifliyidir. Artıq System imtiyazı əldə etmiş təcavüzkarın lokal imtiyaz yüksəltməsinə (local escalation of privilege) imkan verə bilər. Təsirlənmiş sistemi qorumaq üçün ALPS11049569 nömrəli yamaq (patch) tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
What prerequisite must an attacker have to successfully exploit CVE-2026-20485?
The attacker must have already obtained System privilege.
Which patch should be applied to mitigate the risk associated with CVE-2026-20485?
Patch ID ALPS11049569 should be applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.