CVE-2026-20820: Windows CLFS Heap Overflow — Privilege Escalation to SYSTEM via Kernel Driver Abuse
April 2026 Patch Tuesday discloses CVE-2026-20820 — a heap-based buffer overflow in Windows CLFS driver enabling local privilege escalation to SYSTEM. CVSS 7.8. Patch immediately: CLFS has a documented history as a ransomware kill chain component.
