Executive brief
A security vulnerability exists in the Windows Cryptographic Services, which are the core components responsible for securing data and managing digital certificates on Windows computers. An attacker who already has basic access to a system could exploit this flaw to view sensitive information they are not authorized to see. This could lead to the exposure of private data or credentials, potentially compromising the confidentiality of the affected machine.
Technical details
An information disclosure vulnerability (CWE-200) exists in Windows Cryptographic Services. The flaw allows an authenticated attacker with local access to the system to bypass intended access restrictions and view sensitive information. The vulnerability is triggered when the cryptographic service fails to properly protect data from unauthorized local actors. Successful exploitation results in high confidentiality impact but does not allow for data modification or service disruption. Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server 2012 to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD.
- 2026-07-14: advisory: MSRC advisory published.