Microsoft Windows VBS Enclave Information Disclosure Vulnerability
Vulnerability
A vulnerability allowing untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave could enable an unauthorized attacker to locally disclose information. This issue affects multiple versions of Windows 11, including 24H2 and 25H2 for both x64-based and ARM64-based systems, as well as Windows 11 Version 23H2 for x64-based and ARM64-based Systems.
Impact
Exploitation of this vulnerability could allow an attacker to access Virtual Trust Level 1 (VTL1) data from Virtual Trust Level 0 (VTL0), the least privileged level.
Remediation
Users can download the security update for this vulnerability via the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5074109 and KB5073455.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
