Executive brief
A vulnerability in the Windows Client-Side Caching (CSC) Service could allow an authorized user to access information they should not be able to see. This service is responsible for making network files available offline; an exploit could lead to the unauthorized disclosure of sensitive local data. To use this flaw, an attacker must already have the ability to log onto the affected system.
Technical details
An improper access control vulnerability (CWE-284) exists in the Windows Client-Side Caching (CSC) Service. The flaw allows a locally authenticated attacker with low privileges to bypass security restrictions and gain unauthorized access to sensitive information stored within the CSC cache. The attack vector is local, meaning the attacker must have existing credentials and the ability to execute code on the target system. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2008 R2 Service Pack 1
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory