Junglewise Threat Intelligence

CVE-2026-69294: Microsoft COM information disclosure via error messages

CVE-2026-69294 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Microsoft COM (Component Object Model), a core Windows technology for inter-application communication, contains a flaw that allows authorized local users to extract sensitive information through error messages. An attacker with local system access could exploit this to gather system details or credentials, potentially enabling lateral movement or privilege escalation on a compromised machine.

Technical details

The vulnerability is a sensitive information disclosure (CWE-209) in Microsoft COM for Windows. Error messages generated by COM contain sensitive data such as system paths, internal identifiers, or other confidential information that should not be exposed. The attack requires local access and authorization to trigger the error condition that reveals the information. An authenticated local attacker can induce COM to generate the error and read the disclosed details, which could facilitate further attacks. A security patch from Microsoft is available.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References

Related threats