Executive brief
The Windows Program Compatibility Assistant Service improperly logs sensitive information to local log files. An authorized user with local access to the affected system can read these log files to discover confidential data, including credentials or other private details that should not be exposed. This vulnerability could compromise user privacy and enable lateral movement or credential theft within an organization.
Technical details
This vulnerability is an information disclosure flaw in the Windows Program Compatibility Assistant Service, which logs sensitive data (such as credentials or private user information) to locally accessible log files. The root cause is insufficient sanitization of log output before writing to disk. An authenticated local attacker can access these log files to extract sensitive information without requiring elevated privileges. The vulnerability requires local access and user authentication but no special interaction. A patch is expected to be available through the standard Microsoft security update process.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed: Published on NVD and MSRC