Executive brief
A security vulnerability exists in the Windows Tablet User Interface (TWINUI) subsystem, which handles how the operating system manages application associations and interface elements. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that should normally be protected. This could lead to the exposure of private data or system details, though it does not allow the attacker to take control of the machine or disrupt services directly.
Technical details
An information disclosure vulnerability exists in the Tablet Windows User Interface (TWINUI) Subsystem of Microsoft Windows. The flaw is categorized as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). An attacker with local access and low privileges can exploit this vulnerability without any user interaction to disclose sensitive information from the system. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2016. Microsoft has released security updates to address this issue; users should apply the latest cumulative updates for their respective OS versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-01-13: advisory: Initial disclosure by Microsoft and NVD