Executive brief
A security vulnerability in Windows Management Services could allow a user who already has access to a computer to view sensitive information they are not authorized to see. This component is responsible for managing system configurations and operations across the Windows operating system. An exploit could lead to the exposure of confidential system data, potentially aiding further attacks or compromising privacy.
Technical details
An information disclosure vulnerability (CWE-200) exists in Windows Management Services. The flaw allows an authenticated attacker with local access to the system to disclose sensitive information. The attack vector is local (AV:L) and requires low privileges (PR:L) with no user interaction (UI:N). Successful exploitation results in high confidentiality impact (C:H) but does not affect system integrity or availability. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.8276
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.6809
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.6809
- Microsoft Windows 11 Version 22H2 10.0.22621.0 to 10.0.22621.6491
- Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.6491
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.7623
- Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.8276
- Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.3210
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory