CVE-2026-69351
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: secure@microsoft.com (Secondary)
Description
Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
Affected (24)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.14393.9512 | |
| Before 10.0.17763.9245 | |
| Before 10.0.19044.7725 | |
| Before 10.0.19045.7725 | |
| Before 10.0.22631.7582 | |
| Before 10.0.26100.9445 | |
| Before 10.0.26200.9445 | |
| Before 10.0.28000.2954 | |
| All versions | |
| Before 10.0.14393.9512 | |
| Before 10.0.17763.9245 | |
| Before 10.0.20348.5622 | |
| Before 10.0.26100.33438 |
References (1)
Source: secure@microsoft.com
PatchVendor Advisory
Timeline
No history available yet.