CVE-2026-37452: Infoleak
Published Jun 25, 2026
·Updated
Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component
Affected Software
1 affected component
NBFoundation MSI NBFoundation Service=2.0.2506.1201
Event History
Jun 25, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-37452?
CVE-2026-37452 has a severity score of 7.5, classified as high.
2
How do I fix CVE-2026-37452?
To fix CVE-2026-37452, update the MSI NBFoundation Service to the latest version provided by the vendor.
3
What information can be leaked due to CVE-2026-37452?
CVE-2026-37452 can allow attackers to obtain sensitive information via the MSIAPService.exe component.
4
Which version of MSI NBFoundation Service is vulnerable to CVE-2026-37452?
MSI NBFoundation Service version 2.0.2506.1201 is vulnerable to CVE-2026-37452.
5
What type of vulnerability is CVE-2026-37452 classified as?
CVE-2026-37452 is classified as an insecure permissions vulnerability.