Executive brief
Windows Encrypting File System (EFS) is the built-in encryption feature that protects sensitive files on Windows computers. An authorized local user can trigger a buffer over-read flaw to read memory contents that should not be accessible, potentially exposing sensitive data like encryption keys or other system information stored in memory.
Technical details
A buffer over-read vulnerability exists in the Windows Encrypting File System (EFS) implementation. The flaw allows an authorized local attacker to read beyond allocated buffer boundaries, potentially disclosing sensitive information from memory. The attack requires local access and existing user privileges on the system. No network access or user interaction is required beyond the attacker's authenticated local session. Microsoft has issued a security patch to remediate this issue.
Affected products
- Microsoft Windows Multiple versions
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: CVE-2026-69794 published