Executive brief
A security vulnerability has been identified in the Windows Kernel, the core component of the Microsoft Windows operating system. This flaw allows an unauthorized attacker to access sensitive information remotely over a network without needing a password or user interaction. Such an exploit could lead to the exposure of private data or help an attacker gain a deeper foothold within a corporate network.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Windows Kernel, leading to unauthorized information disclosure (CWE-200). The vulnerability is exploitable over the network without authentication (AV:N/PR:N) and requires no user interaction. An attacker can leverage this to read sensitive memory contents, potentially bypassing security mitigations or leaking system secrets. Microsoft has released security updates for affected versions of Windows 10, Windows 11, and Windows Server 2016 to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates released by Microsoft