Impact
An out‑of‑bounds read in the Windows GDI subsystem allows an unauthorized attacker to read memory beyond the intended bounds, exposing sensitive information that resides in the local process memory. The weakness is identified as a buffer overread (CWE‑125) and does not provide direct code execution or privilege escalation capabilities.
Affected Systems
The vulnerability affects Microsoft Windows 10 releases 21H2 and 22H2, Windows 11 releases 22H3, 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2022 and Windows Server 2025, including their Server Core installations.
Risk and Exploitability
The base CVSS score of 5.5 indicates moderate severity. EPSS data is not available and the vulnerability is not listed as a Known Exploited Vulnerability by CISA. The description suggests that an attacker must be able to execute code locally or otherwise interact with the system directly; remote exploitation is not indicated and is therefore considered unlikely. In environments where sensitive data is processed locally, the risk of information leakage remains moderate but is limited to users with local access.
OpenCVE Enrichment