Executive brief
A vulnerability in Windows Cryptographic Services could allow an authorized user on a computer to access sensitive information they should not be able to see. This component is responsible for handling secure data encryption and digital signatures across the operating system. An exploit could lead to the exposure of confidential system or user data, potentially compromising the privacy of the affected machine.
Technical details
An information disclosure vulnerability (CWE-200) exists in Windows Cryptographic Services. The flaw allows a locally authenticated attacker with low privileges to bypass intended information access restrictions. By exploiting this vulnerability, an attacker can gain access to sensitive data handled by the cryptographic subsystem. The attack requires local access to the target system but no user interaction. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory