Executive brief
Windows RNDIS (Remote Network Driver Interface Specification) is a network driver component used to enable communication between devices and operating systems. A heap-based buffer overflow in this component could allow an attacker with physical access to a device to read sensitive information from system memory, potentially exposing credentials, keys, or other confidential data.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows RNDIS driver that can be exploited through a physical attack vector. The vulnerability allows an attacker to read (disclose) information from heap memory. Exploitation requires physical access to the affected device and does not require authentication or network access. The attacker can craft malicious input to trigger the overflow and extract sensitive data from process memory. Patches are available from Microsoft.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed