Impact
ATBroker.exe in Windows Accessibility Infrastructure contains a flaw that allows a local user with authorized access to read sensitive data from the process, thereby exposing confidential information. The vulnerability is classified as CWE‑200 and results in an unauthorized disclosure of data that the component handles.
Affected Systems
Affected releases include Windows 10 versions 1607 through 22H2, Windows 11 versions 23H2 through 26H1, and multiple Windows Server editions from 2012 to 2025, including core installations. All listed variants contain ATBroker.exe, meaning the information‑disclosure risk applies to any machine running these versions.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. Exploitation requires local access from a user who is already authorized to operate on the system; there is no known remote attack vector. Consequently, the primary risk applies to legitimate users who may inadvertently reveal sensitive data in the presence of a local attacker.
OpenCVE Enrichment