Executive brief
Windows Error Reporting is a built-in Windows component that collects and reports system crash and error data. A flaw in how it generates error messages allows an authorized local attacker to view sensitive information that should be restricted, potentially exposing system details or user data stored in crash dumps.
Technical details
The vulnerability exists in Windows Error Reporting's error message generation logic, which inadvertently includes sensitive information in error output. The attack vector is local, requiring an authenticated user account on the affected system. An attacker with local system access can trigger or observe error conditions to extract information that should be protected. The flaw allows information disclosure but does not enable remote code execution or privilege escalation. Microsoft has released security updates to restrict sensitive data from appearing in error messages.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed