Microsoft Windows Client-Side Caching Service Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in the Windows Client-Side Caching (CSC) Service due to improper access control, allowing an authorized attacker to locally disclose information. Exploitation of this vulnerability could enable the attacker to read certain portions of heap memory.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure.

Remediation

Users can apply the security update for this vulnerability, which is available as part of the January 2026 Monthly Rollup, through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5073724 for Windows 10, KB5073723 for Windows Server 2019, and KB5073457 for Windows Server 2022.

Added: Jan 13, 2026, 7:59 PM
Updated: Jan 13, 2026, 7:59 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
2.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.