CVE-2026-49165
Analyzed Analyzed - Analysis Complete

Use of Uninitialized Resource in Windows App Store Allows Local Information Disclosure

Vulnerability report for CVE-2026-49165, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-29

Assigner: Microsoft Corporation

Description

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-29
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-03
NVD
EUVD

Affected Vendors & Products

Showing 20 associated CPEs
Vendor Product Version / Range
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-908 The product uses or accesses a resource that has not been initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-49165 is a vulnerability in Microsoft Windows App Store where an uninitialized resource is used. This flaw allows an authorized attacker with local access to disclose sensitive information from the system.

The vulnerability is classified as an information disclosure issue, meaning it does not directly allow code execution or system takeover but can expose confidential data.

Detection Guidance

The provided context does not specify exact detection methods or commands for identifying the use of uninitialized resources in Microsoft Windows App Store (CVE-2026-49165). Detection may require specialized tools or updates from Microsoft to scan for vulnerable components.

To check for vulnerable versions, you can verify the installed version of the Windows App Store application. However, the context does not provide specific version details or commands for this purpose.

Microsoft may release detection guidance or updates via their security advisory. Refer to the official Microsoft update guide for any available detection tools or scripts.

Impact Analysis

If exploited, this vulnerability could impact you in the following ways:

  • An attacker with local access to your system could disclose sensitive information stored or processed by the Windows App Store.
  • The exposed information might include user data, credentials, or other confidential details, depending on what the uninitialized resource contains.

Since the attacker must be authorized (have local access), the risk is higher in shared or multi-user environments where multiple individuals have access to the same system.

Compliance Impact

This vulnerability could affect compliance with standards and regulations in the following ways:

  • GDPR: If the disclosed information includes personal data of EU citizens, this could constitute a data breach under GDPR, requiring notification to authorities and affected individuals. Failure to protect such data may result in fines or penalties.
  • HIPAA: If the Windows App Store processes or stores protected health information (PHI), unauthorized disclosure due to this vulnerability could violate HIPAA's Privacy and Security Rules, leading to potential legal and financial consequences.

Organizations must assess whether the affected system handles regulated data and take appropriate measures to mitigate the risk, such as applying patches or implementing compensating controls.

Mitigation Strategies

Apply the latest security updates provided by Microsoft for the Windows App Store. The official Microsoft update guide for CVE-2026-49165 should include patches or mitigations.

  • Check the Microsoft Security Response Center (MSRC) portal for the latest advisory and follow their recommended actions.
  • Ensure all systems are running the most recent version of Windows and the Windows App Store to reduce exposure.
  • Monitor Microsoft’s official communications for additional mitigations or workarounds if a patch is not immediately available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49165. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart