Executive brief
A vulnerability exists in the Microsoft Windows Capability Access Management Service, which manages how applications access system features like the camera or microphone. An attacker with local access to a computer could exploit this flaw to view sensitive information that should normally be protected. This could lead to the unauthorized disclosure of system or user data, potentially aiding in further attacks.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists within the Capability Access Management Service (camsvc) in multiple versions of Windows 11 and Windows Server 2025. The flaw is triggered when the service improperly handles memory buffers, allowing a local, unauthorized attacker to read data outside of the intended memory space. This can result in the disclosure of sensitive information from the service's memory. The attack requires local access but no special privileges or user interaction. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 up to (excluding) 10.0.26100.7623
- Microsoft Windows 11 Version 25H2 10.0.26200.0 up to (excluding) 10.0.26200.7623
- Microsoft Windows Server 2025 10.0.26100.0 up to (excluding) 10.0.26100.32230
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory