Executive brief
Windows Mobile Broadband is a Windows component that manages cellular and mobile network connectivity for Windows devices. An out-of-bounds read vulnerability allows an attacker on the network to read sensitive information from affected devices without authorization, potentially exposing customer data or system configuration details.
Technical details
An out-of-bounds read vulnerability exists in Windows Mobile Broadband, a Windows component responsible for managing mobile broadband connectivity. The vulnerability can be exploited over the network by an unauthenticated attacker to read memory outside the intended boundaries of a data structure, leading to information disclosure. The root cause involves improper bounds checking in memory access operations. Successful exploitation allows an attacker to extract sensitive data from the affected system's memory without requiring user interaction or authentication. Microsoft has released security updates to address this vulnerability.
Affected products
- Microsoft Windows Mobile Broadband
Timeline
- 2026-09-08: disclosed