Executive brief
A security vulnerability exists in the Windows feature that provides isolated, secure environments for sensitive data, known as Virtualization-Based Security (VBS) Enclaves. An attacker with local access to a system could exploit this flaw to view information that is supposed to be protected and hidden within these secure zones. This could lead to the exposure of sensitive system data, though it does not allow the attacker to modify files or crash the computer directly.
Technical details
An untrusted pointer dereference vulnerability (CWE-822) exists in the Windows Virtualization-Based Security (VBS) Enclave. The flaw allows a local, unauthorized attacker to trigger the dereference of a pointer provided from an untrusted source, leading to unauthorized information disclosure from the secure enclave. The attack vector is local, requiring the attacker to have a presence on the target system, but it does not require elevated privileges or user interaction. Microsoft has released security updates to address this issue across affected versions of Windows 11.
Affected products
- Microsoft Windows 11 Version 23H2 up to (excluding) 10.0.22631.6491
- Microsoft Windows 11 Version 24H2 up to (excluding) 10.0.26100.7623
- Microsoft Windows 11 Version 25H2 up to (excluding) 10.0.26200.7623
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory