ZeroHour

CVE-2026-83501

mass

Out-of-Bounds Read in Windows Virtualization-Based Security (VBS) Enclave

CVSS 3.1
5.5 medium
EPSS
<1%p24
Published
()
Modified
AI analysis

An out-of-bounds read (CWE-125) in the Windows Virtualization-Based Security (VBS) Enclave allows a locally authenticated, low-privilege attacker to read memory beyond the enclave's intended boundary. It is triggered by code running locally under an authorized account that interacts with the enclave, with no user interaction required. The result is information disclosure only - potentially leaking data the enclave was meant to isolate, such as secrets or protected content - with no impact on integrity or availability. Any Windows system with VBS Enclave support is affected; Microsoft patched the issue in its September 2026 Patch Tuesday release, which fixed 974 vulnerabilities. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS assigns roughly a 0.3 percent 30-day exploitation probability, so no exploitation is currently known.

What to do: Install the September 2026 Windows security updates that include the fix for CVE-2026-83501, prioritizing shared workstations, terminal servers and enterprise/developer systems where untrusted local users can run code and VBS enclaves are in use. Check whether VBS is running and whether any deployed applications rely on enclaves (for example, via the Virtualization-based security status in msinfo32). Given no public PoC or known exploitation, standard patch-cycle urgency is reasonable.

Affected
Microsoft Windows Virtualization-Based Security (VBS) Enclave
Estimated exposure
masshundreds of millions of Windows devices (VBS/enclave code ships across the >1B-device Windows installed base) — Windows runs on over a billion devices and virtualization-based security is enabled by default on most modern Windows 11 installations, so the vulnerable component is present on hundreds of millions of systems, although only hosts running…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

Vendors
microsoft
Products
windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2025
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

Microsoft Patch Tuesday Update September 2026 – 974 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities across Windows and Office, including two actively exploited Windows privilege-escalation zero-days.

Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities spanning Windows, Office, SQL Server, SharePoint, Exchange, Azure, and developer tools. Two Windows zero-days are confirmed exploited in attacks: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a Windows Update Stack privilege-escalation flaw involving link following. The release also includes Critical fixes for Windows Secure Kernel Mode, VBS Enclave, Excel, and Word.

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs