Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.4

Windows imgsys Component Can Crash System with Elevated Privileges

CVE-2026-20439
Summary

A bug in the Windows imgsys component can cause a system crash if a malicious actor with high-level permissions exploits it. This can happen without any user interaction. To fix this, apply the patch ALPS10431955.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
google android 15.0 –
Original title
In imgsys, there is a possible system crash due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not...
Original description
In imgsys, there is a possible system crash due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431955; Issue ID: MSV-5826.
nvd CVSS3.1 4.4
Vulnerability type
CWE-416 Use After Free
Published: 2 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026