Sceawere

Vulnerability Detail

CVE-2026-59128UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Windows EFS Out-of-Bounds Read

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Windows 10 Version 1607
Attack Type
CWE-125: Out-of-bounds Read
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:18:06.917Z",
  "pubdate": "2026-08-11T17:18:06.917Z",
  "executiveSummary": "An out-of-bounds read vulnerability exists within the Windows Encrypting File System (EFS). This flaw allows an authorized attacker to achieve local information disclosure on affected Windows systems. The primary impact involves the unauthorized extraction of sensitive memory contents or system data, potentially exposing cryptographic material or internal structures processed by the affected component. Exploitation of this vulnerability requires local access to the target host and authorization credentials, meaning an untrusted remote entity cannot exploit this vector directly without prior local access. The risk implications include the breach of confidentiality boundaries within the operating system architecture, allowing local users to harvest data they are not normally permitted to view. Remediation depends on applying official vendor patches as supplied through standard update channels for the impacted Windows Encrypting File System component.",
  "technicalDetails": "The vulnerability is classified as an out-of-bounds read residing within the Windows Encrypting File System (EFS). The root cause stems from improper input validation or boundary verification during the processing of specific data structures within the vulnerable component, enabling memory reads past the allocated buffer boundary. Exploitation occurs when an authorized local attacker interacts with the Windows Encrypting File System through specialized system calls, crafted file operations, or API interfaces that trigger the flawed memory handling routine. During the attack flow, the vulnerable function reads adjacent memory regions instead of properly terminating or constraining the read operation to the legitimate buffer boundaries. Because the operation is an out-of-bounds read rather than a write, arbitrary code execution is typically not the primary objective; rather, the payload behavior centers on capturing the contents of adjacent kernel or user-space memory allocations. This leaked memory may contain sensitive data structures, encryption keys, or internal operational states. The attack vector is strictly local, requiring the execution of native instructions or custom tooling on the targeted machine by an entity that already possesses local authorization. There are no network exposure vectors associated with this specific flaw, as the vulnerable Windows Encrypting File System logic is handled internally by the operating system kernel or associated local subsystem binaries. Post-exploitation impact is bound to local information disclosure, which can subsequently facilitate secondary attacks if the leaked memory yields reusable credentials, session tokens, or internal memory addresses useful for bypassing exploit mitigations like ASLR."
}
CVE-2026-59128: Windows EFS Out-of-Bounds Read (MEDIUM Severity, CVSS: 5.5) - Sceawere