Executive brief
A vulnerability in Windows Internet Connection Sharing (ICS) could allow an attacker with physical access to a computer to view sensitive information. ICS is a feature that allows one computer to share its internet connection with other devices on a local network. To exploit this, an attacker must have direct physical access to the machine, limiting the risk to scenarios where hardware is left unattended in insecure locations.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists within the Windows Internet Connection Sharing (ICS) service. The flaw is triggered when the service improperly handles memory buffers, allowing an attacker to read data beyond the intended memory range. Exploitation requires physical access to the target system (AV:P) but does not require prior authentication or user interaction. Successful exploitation results in the disclosure of sensitive information from the system's memory. Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2008 R2 Service Pack 1
Timeline
- 2026-01-13: advisory: Initial publication of CVE-2026-20828 by Microsoft and NVD.