Important CVSS 5.5 EPSS 0.00387 🔬 Patch diffed 2026-08 archive

Executive Summary

Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.

Overview

5.5
CVSS MEDIUM
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Information Disclosure
Released Aug 11 2026
Last Updated Aug 11 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00387 — 0.31808 percentile
NVD CVSS 5.5 MEDIUM — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
None
AVAILABILITY
None
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 4.8

EPSS Score

0.00387
probability of exploitation in the next 30 days
0.31808 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

22 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1607 for 32-bit Systems 5120418 (Security Update) Important Information Disclosure Yes
Windows 10 Version 1607 for x64-based Systems 5120418 (Security Update) Important Information Disclosure Yes
Windows 10 Version 1809 for 32-bit Systems 5120238 (Security Update) Important Information Disclosure Yes
Windows 10 Version 1809 for x64-based Systems 5120238 (Security Update) Important Information Disclosure Yes
Windows 10 Version 21H2 for 32-bit Systems 5120249 (Security Update) Important Information Disclosure Yes
Windows 10 Version 21H2 for ARM64-based Systems 5120249 (Security Update) Important Information Disclosure Yes
Windows 10 Version 21H2 for x64-based Systems 5120249 (Security Update) Important Information Disclosure Yes
Windows 10 Version 22H2 for 32-bit Systems 5120249 (Security Update) Important Information Disclosure Yes
Windows 10 Version 22H2 for ARM64-based Systems 5120249 (Security Update) Important Information Disclosure Yes
Windows 10 Version 22H2 for x64-based Systems 5120249 (Security Update) Important Information Disclosure Yes
Windows 11 Version 23H2 for ARM64-based Systems 5120240 (Security Update) Important Information Disclosure Yes
Windows 11 Version 23H2 for x64-based Systems 5120240 (Security Update) Important Information Disclosure Yes
Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Information Disclosure 5101650 Base: 5.5 Temporal: 4.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Information Disclosure 5101650 Base: 5.5 Temporal: 4.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Information Disclosure 5101650 Base: 5.5 Temporal: 4.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Information Disclosure 5101650 Base: 5.5 Temporal: 4.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5121000 (Security Update) Important Information Disclosure Yes
Windows 11 version 26H1 for x64-based Systems 5121000 (Security Update) Important Information Disclosure Yes
Windows Server 2012 5120386 (Monthly Rollup) Important Information Disclosure Yes
Windows Server 2012 (Server Core installation) 5120386 (Monthly Rollup) Important Information Disclosure Yes
Windows Server 2012 R2 5120385 (Monthly Rollup) Important Information Disclosure Yes
Windows Server 2012 R2 (Server Core installation) 5120385 (Monthly Rollup) Important Information Disclosure Yes
Windows Server 2016 5120418 (Security Update) Important Information Disclosure Yes
Windows Server 2016 (Server Core installation) 5120418 (Security Update) Important Information Disclosure Yes
Windows Server 2019 5120238 (Security Update) Important Information Disclosure Yes
Windows Server 2019 (Server Core installation) 5120238 (Security Update) Important Information Disclosure Yes

Patches

7 patches
Article Type Restart
5120418 Security Update Yes
5120238 Security Update Yes
5120249 Security Update Yes
5120240 Security Update Yes
5121000 Security Update Yes
5120386 Monthly Rollup Yes
5120385 Monthly Rollup Yes

Patch Diff

ghidriff · dot3svc.dll (KB5121003)

Buffer over-read (CWE-126) in the Windows Wired AutoConfig service dot3svc.dll RpcUIResponse handler, local information disclosure of privileged-process heap memory. dot3svc.dll (802.1X wired authentication) exposes RpcUIResponse, which receives a UI response buffer from the client containing a _DOT3_UI_REQUEST structure and forwards it to Dot3AcmUIResponse. PRE: the handler took the embedded request pointer (*(param_3+8)) and used it without validating that the supplied buffer was at least the size of the structure, so a client-supplied buffer smaller than the _DOT3_UI_REQUEST record caused the service to read past the end of the buffer - a buffer over-read that discloses adjacent heap memory of the privileged (SYSTEM) service. Diff of dot3svc.dll 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: the parameter is now a counted buffer (uint *param_3) and, gated behind CFR flag Feature_2872289593, RpcUIResponse validates the request pointer is non-null AND the buffer length (*param_3) is at least 0x28 (the structure size) before use - if (request == 0 || *param_3 < 0x28) return ERROR_INVALID_PARAMETER (0x57) - so an undersized buffer is rejected instead of over-read.

Pre-patch version 10.0.26100.8972 Download
Post-patch version 10.0.26100.9168 Download
Function Address Change Note
RpcUIResponse code change code (buffer length validated before reading the request, CFR-gated) Param changed to counted 'uint *param_3'. Pre: passed *(param_3+8) to Dot3AcmUIResponse with no size check. Post (Feature_2872289593): if ((*(longlong*)(param_3+2) == 0) || (*param_3 < 0x28)) return 0x57 (ERROR_INVALID_PARAMETER) before use - requires the buffer to hold the full 0x28-byte _DOT3_UI_REQUEST.
Feature_2872289593 gate added (CFR gate) CFR flag gating the buffer-length validation; the original unchecked read still ships when disabled.
View full diff report View RCA report

Attack Path

An undersized UI-response buffer makes the Wired AutoConfig service read past it, leaking heap memory

Attack path for CVE-2026-62730 An undersized UI-response buffer makes the Wired AutoConfig service read past it, leaking heap memory 01 — ENTRY Local user calls the Wired AutoConfig RpcUIResponse RPC dot3svc.dll (SYSTEM, 802.1X) receives a UI response buffer with an embedded _DOT3_UI_REQUEST. AV:L/PR:L/AC:L. 02 — CONTROLLED INPUT Supplies a buffer smaller than the _DOT3_UI_REQUEST structure The declared/supplied buffer is under 0x28 bytes. 03 — MISSING CHECK Handler reads the request without a size check (CWE-126) Pre-patch it uses *(param_3+8) / the structure fields past the end of the undersized buffer. 04 — PATH Service reads adjacent heap memory The over-read pulls bytes beyond the buffer from the privileged process heap. 05 — PRIMITIVE Buffer over-read -> heap information disclosure The Aug 2026 fix (Feature_2872289593) requires *param_3 >= 0x28 (and a non-null request) before reading.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

Detection Rules

Acknowledgments

k0shl