Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.