Executive brief
Windows OLE DB is a core database connectivity component used by many enterprise applications to access and manage data. An out-of-bounds memory read vulnerability allows an attacker on the network to extract sensitive information from affected systems without requiring authentication, potentially exposing confidential business data or system details.
Technical details
This vulnerability is an out-of-bounds read in Windows OLE DB (Object Linking and Embedding Database), a data-access layer component used by Windows and dependent applications. The flaw allows an attacker to read memory beyond intended boundaries, leading to information disclosure. The vulnerability is accessible over the network without requiring authentication. An attacker can exploit this to extract sensitive data from memory, such as credentials, encryption keys, or application data. A security patch is expected to be available from Microsoft.
Affected products
- Microsoft Windows OLE DB
Timeline
- 2026-09-08: disclosed