Executive brief
A security vulnerability exists in the Windows Universal Plug and Play (UPnP) service, which is used by the operating system to discover and connect to networked devices like printers and cameras. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that should normally be protected. This could lead to the exposure of private data or help an attacker gain further control over the system.
Technical details
A vulnerability classified as 'Use of Uninitialized Resource' (CWE-908) exists within the Windows Universal Plug and Play (UPnP) component, specifically in upnp.dll. The flaw allows a local attacker with low-level privileges to access memory contents that have not been properly initialized, potentially leading to the disclosure of sensitive information from the process memory. The attack vector is local, requiring the attacker to execute a specially crafted application on the target system. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server 2012.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory