Executive brief
Windows Connected User Experiences and Telemetry is a Microsoft service that collects diagnostic and usage data from Windows systems. A flaw in access controls allows an authorized local user to access sensitive telemetry information they should not have permission to view, potentially exposing personal or system configuration details.
Technical details
This vulnerability is an insufficient granularity of access control (privilege escalation / authorization bypass) in the Windows Connected User Experiences and Telemetry service. The root cause is inadequate permission checks that fail to properly restrict which local users can access specific telemetry data. An authenticated local attacker can bypass access controls to read sensitive information that should be restricted. The attack requires local system access and existing user authentication. No privilege elevation to SYSTEM or admin is required. The vulnerability enables information disclosure of confidential telemetry and system configuration data, though it does not allow modification or service disruption.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed