CVE-2026-62730 — Windows Wired AutoConfig Service Information Disclosure Vulnerability
Executive Summary
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems | 5120418 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5120418 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5120238 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5120238 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5120249 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5120249 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5120240 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5120240 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Information Disclosure 5101650 Base: 5.5 Temporal: 4.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Information Disclosure 5101650 Base: 5.5 Temporal: 4.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Information Disclosure 5101650 Base: 5.5 Temporal: 4.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Information Disclosure 5101650 Base: 5.5 Temporal: 4.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5121000 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5121000 (Security Update) |
Important | Information Disclosure | Yes |
| Windows Server 2012 | 5120386 (Monthly Rollup) |
Important | Information Disclosure | Yes |
| Windows Server 2012 (Server Core installation) | 5120386 (Monthly Rollup) |
Important | Information Disclosure | Yes |
| Windows Server 2012 R2 | 5120385 (Monthly Rollup) |
Important | Information Disclosure | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5120385 (Monthly Rollup) |
Important | Information Disclosure | Yes |
| Windows Server 2016 | 5120418 (Security Update) |
Important | Information Disclosure | Yes |
| Windows Server 2016 (Server Core installation) | 5120418 (Security Update) |
Important | Information Disclosure | Yes |
| Windows Server 2019 | 5120238 (Security Update) |
Important | Information Disclosure | Yes |
| Windows Server 2019 (Server Core installation) | 5120238 (Security Update) |
Important | Information Disclosure | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5120418 |
Security Update | Yes |
5120238 |
Security Update | Yes |
5120249 |
Security Update | Yes |
5120240 |
Security Update | Yes |
5121000 |
Security Update | Yes |
5120386 |
Monthly Rollup | Yes |
5120385 |
Monthly Rollup | Yes |
Patch Diff
Buffer over-read (CWE-126) in the Windows Wired AutoConfig service dot3svc.dll RpcUIResponse handler, local information disclosure of privileged-process heap memory. dot3svc.dll (802.1X wired authentication) exposes RpcUIResponse, which receives a UI response buffer from the client containing a _DOT3_UI_REQUEST structure and forwards it to Dot3AcmUIResponse. PRE: the handler took the embedded request pointer (*(param_3+8)) and used it without validating that the supplied buffer was at least the size of the structure, so a client-supplied buffer smaller than the _DOT3_UI_REQUEST record caused the service to read past the end of the buffer - a buffer over-read that discloses adjacent heap memory of the privileged (SYSTEM) service. Diff of dot3svc.dll 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: the parameter is now a counted buffer (uint *param_3) and, gated behind CFR flag Feature_2872289593, RpcUIResponse validates the request pointer is non-null AND the buffer length (*param_3) is at least 0x28 (the structure size) before use - if (request == 0 || *param_3 < 0x28) return ERROR_INVALID_PARAMETER (0x57) - so an undersized buffer is rejected instead of over-read.
| Function | Address | Change | Note |
|---|---|---|---|
RpcUIResponse |
code change |
code (buffer length validated before reading the request, CFR-gated) | Param changed to counted 'uint *param_3'. Pre: passed *(param_3+8) to Dot3AcmUIResponse with no size check. Post (Feature_2872289593): if ((*(longlong*)(param_3+2) == 0) || (*param_3 < 0x28)) return 0x57 (ERROR_INVALID_PARAMETER) before use - requires the buffer to hold the full 0x28-byte _DOT3_UI_REQUEST. |
Feature_2872289593 |
gate |
added (CFR gate) | CFR flag gating the buffer-length validation; the original unchecked read still ships when disabled. |
Attack Path
An undersized UI-response buffer makes the Wired AutoConfig service read past it, leaking heap memory
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
Detection Rules
Acknowledgments
k0shl