Executive brief
Windows Event Logging Service, a core Windows system component responsible for recording system and application events, is vulnerable to an out-of-bounds read that could allow an attacker to execute code remotely without authentication. If exploited, this could enable attackers to gain unauthorized control over affected systems, leading to data theft, malware installation, or operational disruption.
Technical details
An out-of-bounds read vulnerability exists in the Windows Event Logging Service, a system service that handles event log operations. The vulnerability can be triggered over the network and does not require authentication or user interaction, allowing a remote attacker to read memory beyond allocated buffer boundaries. Successful exploitation could lead to information disclosure or remote code execution on affected Windows systems. A patch is available from Microsoft.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed