Executive brief
Windows Image Acquisition is a Windows component used to manage scanners and cameras. An authorized attacker with local access could read information outside allocated memory, potentially exposing sensitive data from the system.
Technical details
The vulnerability is an out-of-bounds read in Windows Image Acquisition triggered through specially crafted requests. The flaw allows an authenticated local attacker to read memory contents that should not be accessible. Attack preconditions include local system access and valid user authentication. Successful exploitation could disclose system information or other sensitive data resident in memory. A patch is expected from Microsoft as part of their regular security update cycle.
Affected products
- Microsoft Windows Image Acquisition <UNKNOWN>
Timeline
- 2026-09-08: disclosed