Executive brief
Windows Universal Plug and Play (UPnP) Device Host is a system service that enables devices on a local network to discover and communicate with each other. An authorized local attacker could exploit this vulnerability to access private personal information stored or accessible through the UPnP service, potentially exposing sensitive data.
Technical details
This vulnerability is an information disclosure flaw in Windows UPnP Device Host that allows an authorized local attacker to access private personal information. The attack requires local access and authorization credentials, limiting exposure to on-premises threats. The vulnerability enables unauthorized data access within the UPnP subsystem, potentially exposing sensitive information that should be protected. Microsoft has addressed this issue through security updates for affected Windows versions.
Affected products
- Microsoft Windows UPnP Device Host
Timeline
- 2026-09-08: disclosed