Executive brief
A security vulnerability in the Windows Application Identity (AppID) Subsystem could allow a user already logged into a computer to access sensitive information they are not authorized to see. This component is responsible for identifying and verifying the identity of applications running on the system. While an attacker must already have local access to the machine, this flaw could lead to the exposure of confidential system or user data.
Technical details
An information disclosure vulnerability exists in the Windows Application Identity (AppID) Subsystem, classified as CWE-200. The flaw allows a locally authenticated attacker with low privileges to bypass intended access restrictions and read sensitive data from the subsystem. The attack vector is local, meaning the attacker must have the ability to execute code on the target system, but no user interaction is required. Successful exploitation results in a high impact on confidentiality, though integrity and availability are not directly affected. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: advisory: Microsoft published the security advisory and NVD entry.