Executive brief
Windows Network Connection Broker is a system service that manages network connectivity on Windows computers. A use-after-free vulnerability allows a local user with system access to read sensitive information from memory, potentially exposing passwords, tokens, or other confidential data stored by the system.
Technical details
A use-after-free vulnerability exists in Windows Network Connection Broker, a system component responsible for managing network connections. The vulnerability allows an authorized local attacker to access freed memory regions, potentially reading sensitive data. Exploitation requires local access and authentication; the attack cannot be performed remotely over a network. An attacker can disclose information resident in memory, though the specific data exposed depends on system state and running processes. A patch from Microsoft is expected to be available through standard Windows Update channels.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed