AI analysis
An out-of-bounds read (CWE-125) in the Windows Virtualization-Based Security (VBS) Enclave allows a locally authenticated, low-privilege attacker to read memory beyond the enclave's intended boundary. It is triggered by code running locally under an authorized account that interacts with the enclave, with no user interaction required. The result is information disclosure only - potentially leaking data the enclave was meant to isolate, such as secrets or protected content - with no impact on integrity or availability. Any Windows system with VBS Enclave support is affected; Microsoft patched the issue in its September 2026 Patch Tuesday release, which fixed 974 vulnerabilities. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS assigns roughly a 0.3 percent 30-day exploitation probability, so no exploitation is currently known.
What to do: Install the September 2026 Windows security updates that include the fix for CVE-2026-83501, prioritizing shared workstations, terminal servers and enterprise/developer systems where untrusted local users can run code and VBS enclaves are in use. Check whether VBS is running and whether any deployed applications rely on enclaves (for example, via the Virtualization-based security status in msinfo32). Given no public PoC or known exploitation, standard patch-cycle urgency is reasonable.
Affected
| Microsoft Windows Virtualization-Based Security (VBS) Enclave | — |
Estimated exposure
masshundreds of millions of Windows devices (VBS/enclave code ships across the >1B-device Windows installed base) — Windows runs on over a billion devices and virtualization-based security is enabled by default on most modern Windows 11 installations, so the vulnerable component is present on hundreds of millions of systems, although only hosts running…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.