Executive brief
The Windows Program Compatibility Assistant Service, a system component that helps ensure compatibility of older applications, contains a flaw that allows an authorized attacker to read sensitive information from system memory and transmit it over the network. This could lead to the exposure of confidential data such as cached credentials, system configuration details, or other protected information stored in memory.
Technical details
The vulnerability is an out-of-bounds read in the Windows Program Compatibility Assistant Service, allowing an authenticated attacker to access memory regions outside the intended bounds of a buffer or data structure. The attack requires network reachability to the affected service and authorization to interact with it. By crafting malicious requests, an attacker can trigger the out-of-bounds read to disclose sensitive information resident in system memory. The vulnerability does not require code execution or elevated privileges beyond the authentication requirement. Microsoft has released patches as part of their security update cycle.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed