ZeroHour

CVE-2026-70579

mass

Out-of-Bounds Read in Windows Mobile Broadband Enables Remote Info Disclosure

CVSS 3.1
7.5 high
EPSS
1%p62
Published
()
Modified
AI analysis

CVE-2026-70579 is an out-of-bounds read (CWE-125) in the Windows Mobile Broadband (WWAN) component that Microsoft rates High (CVSS 7.5). The flaw can be triggered over a network by an unauthorized attacker with no privileges and no user interaction, per the CVSS vector, meaning no local access or victim action is required. A successful exploit reads memory beyond intended boundaries and discloses sensitive information, with impact confined to confidentiality (no integrity or availability impact). Affected systems are Windows machines carrying the Mobile Broadband component — in practice primarily devices equipped with cellular (WWAN) adapters such as business laptops and tablets. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 1.0% chance of exploitation within 30 days (62nd percentile).

What to do: Check whether endpoints have a Mobile Broadband/cellular adapter (WWAN service or modem present) and prioritize them for the Microsoft update that addresses this CVE, since the flaw is remotely triggerable with no user interaction. Because there is no known public exploit and EPSS is low, routine patch-cycle remediation is reasonable, but treat internet-exposed or untrusted-network WWAN laptops as higher priority. Exact affected version ranges are not in this data, so verify scope against Microsoft's official advisory before remediation.

Affected
Microsoft Windows Mobile Broadband (WWAN) component
Estimated exposure
masslikely tens of millions of Windows endpoints, but only those with Mobile Broadband/WWAN adapters present — Windows runs on over a billion devices and Mobile Broadband hardware is common in enterprise laptop fleets (WWAN-equipped business notebooks), so the exposed subset plausibly exceeds 1M systems, though the exact install base of the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.

Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.