CVE-2026-78516: Windows Storage Information Disclosure Vulnerability
Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.
Other sources
Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally.
— Microsoft
Windows Storage Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs physical access to the affected system and user interaction. No prior privileges are required.
What is the likely impact if exploitation succeeds?
Successful exploitation can disclose information. The available data does not indicate integrity loss or denial-of-service impact.
Which Windows systems are listed as affected?
The affected software list includes Microsoft Windows 10, Windows 11, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025.