Executive brief
A vulnerability in the Windows Kernel can allow an authorized attacker to access and disclose sensitive system information over a network. While exploiting this flaw requires the attacker to have initial authorization on the system, successful exploitation could expose confidential kernel-level data that could be leveraged for further attacks or reveal system configuration details.
Technical details
This vulnerability is an information disclosure flaw in the Windows Kernel that improperly exposes sensitive system information to an unauthorized control sphere. The vulnerability requires the attacker to be an authorized user with local access to the system. The attack vector is network-based, allowing the attacker to disclose kernel information remotely once the initial authorization requirement is met. An attacker exploiting this flaw can obtain sensitive system information that may facilitate privilege escalation or other follow-on attacks.
Affected products
- Microsoft Windows Kernel
Timeline
- 2026-09-08: disclosed