Executive brief
Windows Overlay Filter is a Windows system component that manages visual overlays and display operations. A buffer over-read vulnerability allows an authorized local attacker to read sensitive information from system memory, potentially exposing credentials, encryption keys, or other confidential data used by the system or other applications.
Technical details
A buffer over-read vulnerability exists in the Windows Overlay Filter driver. The vulnerability allows an authenticated local attacker to read beyond the bounds of an allocated buffer, enabling disclosure of adjacent memory contents. Exploitation requires local system access and user authentication; it cannot be exploited over the network. The flaw may expose sensitive kernel or application data, though code execution is not directly achievable through this vector alone. A patch is available from Microsoft.
Affected products
- Microsoft Windows Overlay Filter
Timeline
- 2026-09-08: disclosed