Description
Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
Published: 2026-06-09
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A memory corruption flaw in the Windows Application Identity (AppID) Subsystem permits an attacker with local authorized access to perform an out‑of‑bounds read, leaking data that may reside in memory. The vulnerability is classified as an out‑of‑bounds read (CWE‑125), which can expose sensitive information such as credentials, tokens, or user data. The impact is limited to confidentiality loss for the local user session and does not enable local privilege escalation or remote code execution.

Affected Systems

Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1 as well as Microsoft Windows Server 2025, including the Server Core installation. The affected platforms are documented by Microsoft’s Windows update guide.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits. The likely attack vector requires the attacker to be an authorized user on the target machine, from which the out‑of‑bounds read may expose memory contents. Because the flaw only reads data locally, the risk is confined to the compromised account and does not spread beyond the host.

Generated by OpenCVE AI on June 9, 2026 at 20:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Microsoft Security Update guide for an availability of a patch for CVE‑2026‑45604.
  • Keep Windows 11 and Windows Server 2025 installed at their latest supported releases once a patch is released to ensure the vulnerability is remediated.
  • Apply the principle of least privilege to applications that run with elevated rights so that a local attacker cannot rely on privileged accounts to benefit from the memory read.
  • Maintain regular security monitoring for anomalous information disclosure events and audit application runtimes for signs of unauthorized memory access.

Generated by OpenCVE AI on June 9, 2026 at 20:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
Title Windows Managed Installer Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-09T21:50:46.193Z

Reserved: 2026-05-12T19:55:45.731Z

Link: CVE-2026-45604

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:17:29.097

Modified: 2026-06-09T19:32:51.440

Link: CVE-2026-45604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T11:15:05Z

Weaknesses