Executive brief
A vulnerability in the Windows Connected User Experiences and Telemetry service could allow a user with basic access to a computer to cause a system crash or service failure. This component is responsible for managing diagnostic data and user experience features across the Windows operating system. While it does not allow for data theft, an exploit could disrupt business operations by making the affected workstation or server unavailable.
Technical details
A denial of service vulnerability exists in the Microsoft Windows Connected User Experiences and Telemetry Service due to improper privilege management (CWE-269). An attacker with local access and low-level user privileges can exploit this flaw to disrupt the service or cause a system-wide denial of service. The attack vector is local and requires no user interaction. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server. Security engineers should verify that systems are updated beyond the specific build numbers listed in the vendor advisory (e.g., 10.0.19045.7184 for Windows 10 22H2).
Affected products
- Microsoft Windows 10 21H2, 22H2
- Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
- Microsoft Windows Server 2022 Standard, 23H2
- Microsoft Windows Server 2025 All versions
Timeline
- 2026-04-14: disclosed: Initial disclosure by Microsoft
- 2026-04-14: advisory: MSRC advisory published
- 2026-05-26: other: NVD record updated with additional references
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32181
- https://www.vicarius.io/vsociety/posts/cve-2026-32181-detection-script-dos-vulnerability-in-windows-connected-user-experiences-and-telemetry-service
- https://www.vicarius.io/vsociety/posts/cve-2026-32181-mitigation-script-dos-vulnerability-in-windows-connected-user-experiences-and-telemetry-service