Executive brief
A security vulnerability exists in the Windows component responsible for identifying and verifying applications. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that should normally be protected. This could lead to the exposure of system secrets or data from other users, potentially aiding in further attacks on the organization.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists within the Windows Application Identity (AppID) Subsystem. The flaw is triggered when the subsystem improperly handles memory buffers during application identification processes. To exploit this, an attacker must have local access to the system with low-level privileges. Successful exploitation allows the attacker to read data from memory locations outside of the intended buffer, leading to the disclosure of sensitive information from the kernel or other processes. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory