Executive brief
A security vulnerability exists in the Windows Kernel, the core component of the Windows operating system. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that should normally be protected. This could lead to the exposure of system secrets or user data, though it does not allow the attacker to take control of the system or delete files directly.
Technical details
An information disclosure vulnerability exists in the Windows Kernel due to an integer underflow (CWE-191) which leads to an out-of-bounds read (CWE-125). The vulnerability is exploitable by a locally authenticated attacker with low privileges. By triggering the underflow, an attacker can read sensitive data from kernel memory that is otherwise restricted. The attack does not require user interaction and has a high impact on confidentiality, though it does not affect system integrity or availability. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 Standard and Server Core
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory