Description
Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 7.5 High
EPSS: 1.0% Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an out‑of‑bounds read in the Windows Mobile Broadband stack that permits an attacker to read protected memory and disclose its contents. The primary consequence is the exposure of sensitive data that should be confined to trusted system processes, directly violating confidentiality. The weakness is defined by CWE-125 and can allow the attacker to harvest arbitrary data from memory associated with the broadband subsystem.

Affected Systems

The affected products include several recent builds of Microsoft Windows: Windows 10 Version 21H2 and 22H2, and Windows 11 Versions 23H2, 24H2, 25H2, 26H1 (both arm64 and x64 where applicable). All listed editions are listed as vulnerable via the provided CPE entries.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity information‑disclosure flaw. With an EPSS score of 1%, indicating low exploitation probability, the lack of a KEV listing suggests no widespread exploit campaigns are known yet, but the condition for compromise is likely a network connection to the vulnerable device. An attacker could trigger the read by sending crafted traffic to the Mobile Broadband component, potentially exposing sensitive data without user interaction. Consequently, operators should treat this as a high‑risk vulnerability that requires timely remediation.

Generated by OpenCVE AI on September 9, 2026 at 20:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft patch released at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70579
  • If a patch cannot be applied immediately, disable the Mobile Broadband service on affected machines to prevent network traffic from reaching the vulnerable component
  • Monitor network interfaces and system logs for unusual activity that may indicate exploitation attempts

Generated by OpenCVE AI on September 9, 2026 at 20:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Vendors & Products Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.
Title Windows Mobile Broadband Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-125
CPEs cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 21h2 Windows 10 21h2 Windows 10 22h2 Windows 10 22h2 Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:36:51.137Z

Reserved: 2026-08-04T19:47:18.931Z

Link: CVE-2026-70579

cve-icon Vulnrichment

Updated: 2026-09-08T20:08:44.159Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:10.850

Modified: 2026-09-24T19:53:19.883

Link: CVE-2026-70579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:54:14Z

Weaknesses