Junglewise Threat Intelligence

CVE-2026-68831: Microsoft Windows Defender Firewall Service information disclosure

CVE-2026-68831 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Defender Firewall Service contains a local information disclosure vulnerability that allows an authenticated attacker to access sensitive files or directories that should be restricted. An attacker with local system access could exploit this to read confidential configuration or system data, potentially exposing security policies or other sensitive information.

Technical details

The vulnerability is a local information disclosure issue in Windows Defender Firewall Service caused by improper access controls on files or directories. An authorized local attacker can access sensitive files or directories that should be restricted to privileged processes. The attack requires local access and authentication; a remote network attack is not possible. Successful exploitation allows the attacker to disclose information locally but does not lead to code execution or privilege escalation. Patches are available from Microsoft.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats