# CVE-2026-62730 — Windows Wired AutoConfig Service `dot3svc.dll` Under-Validated UI-Response Buffer in `RpcUIResponse` → Buffer Over-Read

---

## Summary

| | |
|---|---|
| **Product** | Windows — `dot3svc.dll` (Wired AutoConfig Service; 802.1X wired authentication, SYSTEM) |
| **CVE ID** | CVE-2026-62730 |
| **Impact** | Information Disclosure (privileged-process heap memory) |
| **MSRC severity** | Important |
| **CVSS** | 5.5 / 4.8 — `CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C` |
| **CWE** | CWE-126: Buffer Over-read |
| **Delivery** | Local — a crafted UI-response buffer over the service's RPC interface |
| **KB / Fixed build** | KB5121003 — `dot3svc.dll` 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `dot3svc.dll` 10.0.26100.8972 — SHA256 `1e3b6fe6c82dfcdc0d969e66ac53e58be5aa44eb4144ad1a339f24c856eb4274` |
| **Post-patch binary** | `dot3svc.dll` 10.0.26100.9168 — SHA256 `27c2fdc9f8fadc8d9f08f9524393421f1c2eb776082f769a3d9e363f80552afa` |
| **Feature flag** | `Feature_2872289593` — **the fix is CFR-gated** |
| **Exploitability** | Exploitation Less Likely; not publicly disclosed; not exploited (per MSRC) |

---

## Product Description

`dot3svc.dll` is the Windows **Wired AutoConfig** service (802.1X authentication for
wired networks), which runs as SYSTEM. It exposes `RpcUIResponse`, an RPC method that
receives a UI-response buffer from the caller containing a `_DOT3_UI_REQUEST`
structure and forwards the embedded request to `Dot3AcmUIResponse`.

---

## Vulnerability Summary

Pre-patch, `RpcUIResponse` took the embedded request pointer from the caller-supplied
buffer and used it **without validating that the buffer was at least the size of the
`_DOT3_UI_REQUEST` structure**. A caller supplying a buffer smaller than the record
therefore caused the service to read past the end of the buffer — a buffer over-read
(CWE-126) that discloses adjacent **heap memory of the privileged SYSTEM service**
(per the MSRC FAQ, "view heap memory from a privileged process").

---

## Prerequisites and Constraints

- Local, low-privileged (`PR:L`, `AV:L`, `AC:L`): call the Wired AutoConfig
  `RpcUIResponse` RPC.
- Supply a UI-response buffer shorter than the `_DOT3_UI_REQUEST` structure
  (< `0x28` bytes).
- Result: the service reads beyond the buffer, returning/leaking adjacent heap
  contents.

---

## Vulnerability Details

### Root Cause

The handler used the request structure inside the caller's buffer without checking
the buffer was large enough to contain it, so an undersized buffer was read out of
bounds.

### The patch (confirmed — diff, .8972 → .9168)

The buffer parameter is now a **counted** `uint *param_3`, and, gated behind
`Feature_2872289593`, `RpcUIResponse` validates the request pointer is non-null **and
the buffer length is at least `0x28`** (the structure size) before use:

```c
// RpcUIResponse (10.0.26100.9168) — PATCHED, feature-enabled branch (from the diff)
if (Feature_2872289593__private_IsEnabled()) {
    request = *(longlong *)(param_3 + 2);
    if (request == 0 || *param_3 < 0x28) {         // *** require the full _DOT3_UI_REQUEST ***
        return 0x57;                               // ERROR_INVALID_PARAMETER
    }
}
... Dot3AcmUIResponse(param_2, *(_DOT3_UI_REQUEST **)(param_3 + 8), param_4);
```

With the buffer required to hold the full `0x28`-byte request (and a non-null
request pointer), an undersized buffer is rejected instead of being read past its
end, closing the over-read.

### Patch Completeness Assessment

**CFR-gated behind `Feature_2872289593`.** The length validation runs only when the
flag is enabled; the original unchecked read still ships when disabled. Verify
`Feature_2872289593` is enabled to confirm the fix is live.

---

## Detection Guidance

**Behavioural.** Wired AutoConfig `RpcUIResponse` calls carrying undersized UI-response
buffers (< `0x28` bytes); over-read / anomalous responses from
`dot3svc!RpcUIResponse` on unpatched/flag-disabled builds.

**Config.** The fix is CFR-gated — confirm `Feature_2872289593` is enabled.

---

## References

- MSRC advisory — CVE-2026-62730 (Windows Wired AutoConfig Service Information Disclosure), released 2026-08-11, KB5121003.
- Full binary diff: `/data/patch_diffs/dot3svc_dll-cve-2026-62730-ghidriff.md`
