Executive brief
A security vulnerability exists in Windows Key Guard, a component used to protect sensitive cryptographic keys on Windows devices. An attacker who already has basic access to a computer could exploit this flaw to bypass security protections and potentially access protected information. This could lead to the unauthorized exposure of sensitive data stored on the affected system.
Technical details
This vulnerability is classified as a 'Use of a Cryptographic Primitive with a Risky Implementation' (CWE-1240) within the Windows Key Guard component. An attacker must have local access to the system and be authenticated with low privileges (PR:L) to exploit the flaw. By leveraging the weak cryptographic implementation, the attacker can bypass intended security boundaries to gain unauthorized access to sensitive information (C:H). Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server to address this issue.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory