Sceawere

Vulnerability Detail

CVE-2026-62730UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Windows Wired AutoConfig Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Windows 10 Version 1607
Attack Type
CWE-126: Buffer Over-read
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:18:24.283Z",
  "pubdate": "2026-08-11T17:18:24.283Z",
  "executiveSummary": "A buffer over-read vulnerability has been identified within the Windows Wired AutoConfig Service. This security flaw enables a locally authenticated threat actor to execute unauthorized memory reads, leading to the potential disclosure of sensitive system information. The vulnerability affects the Windows Wired AutoConfig Service component across applicable Microsoft Windows operating system configurations. The primary risk implication centers on unauthorized information disclosure, which could expose critical memory contents or internal state data to local processes. Exploitation of this vulnerability requires the attacker to possess prior local authorization and execution capabilities on the target system. Interaction requirements are minimal, but the adversary must already be authenticated locally to interact with the vulnerable service and trigger the out-of-bounds read condition. The vulnerability does not inherently provide remote code execution or direct privilege escalation capabilities based on the provided disclosure, but the leaked information may facilitate subsequent exploitation phases.",
  "technicalDetails": "The vulnerability resides in the Windows Wired AutoConfig Service, which is responsible for managing IEEE 802.1X authentication for wired network interfaces. The root cause stems from an improper bounds check implementation during the processing of specific input data or internal structures handled by the service component. When the service parses crafted or malformed requests, it fails to adequately validate the length of the input data against the allocated memory buffer size, resulting in a buffer over-read condition.\nExploitation of this vulnerability requires the attacker to have local access and specific authorization to communicate with the Windows Wired AutoConfig Service. The attack flow begins with the authenticated local user formulating a specially crafted request or invoking specific service interfaces exposed by the Wired AutoConfig Service. Upon receiving the input, the vulnerable component attempts to process the data without performing rigorous boundary validation. As the service reads past the allocated buffer boundary, adjacent memory contents are inadvertently accessed and processed.\nDepending on the specific memory layout and contents at the time of the over-read, the service may inadvertently echo or leak sensitive information back to the attacker via return values, error logs, or output buffers. This unauthorized information disclosure allows the adversary to harvest sensitive data residing in kernel or user-mode memory spaces managed by the service. The network exposure of this vulnerability is strictly local, as remote network interfaces typically do not provide direct, unauthenticated or unauthorized access to exploit this specific local service mechanism without intermediary pivoting or prior compromise. Post-exploitation impact is constrained to the leakage of system state data, configuration details, or memory artifacts, which could potentially be leveraged by advanced adversaries to map internal memory layouts or bypass supplementary security controls."
}
CVE-2026-62730: Windows Wired AutoConfig Information Disclosure (MEDIUM Severity, CVSS: 5.5) - Sceawere