Information Disclosure Vulnerability in Windows Event Logging Service by Microsoft
CVE-2026-34348

6.5MEDIUM

Key Information:

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoCπŸ“° News Worthy

What is CVE-2026-34348?

A vulnerability exists in the Windows Event Logging Service due to a failure in its protection mechanisms, allowing an authorized attacker to potentially disclose sensitive information across a network. This could lead to unauthorized access to sensitive data or system information, emphasizing the need for immediate attention to system security and patching.

Affected Version(s)

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9020

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7548

Windows 10 Version 22H2 32-bit Systems 10.0.19045.0 < 10.0.19045.7548

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Passkey attacks abuse Windows logs, Google Password Manager, and Windows Hello to bypass phishing-resistant MFA without breaking FIDO2.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.