Executive brief
Microsoft Account contains a vulnerability where uninitialized memory may be accessed by an authorized user, potentially exposing sensitive information stored in memory. This could allow an authenticated attacker to read data they should not have access to, compromising user privacy and system security.
Technical details
The vulnerability is a use of uninitialized resource (CWE-908) in Microsoft Account that allows information disclosure. An authorized attacker with local access can exploit this flaw to read uninitialized memory regions and potentially disclose sensitive information. The attack requires local access and prior authentication, limiting the attack surface. No evidence of active exploitation in the wild has been reported. A patch is expected to be available through Microsoft's standard security update process.
Affected products
- Microsoft Account
Timeline
- 2026-09-08: disclosed: Published on NVD and MSRC
- other: No evidence of exploitation in wild