Impact
The Windows Snipping Tool contains a vulnerability that exposes sensitive information to unauthorized actors, enabling them to spoof interactions over a network. This information disclosure flaw aligns with CWE‑200 and can compromise confidentiality of data captured by the tool, allowing attackers to masquerade as legitimate users or commands.
Affected Systems
The flaw affects multiple Microsoft Windows releases, including Windows 10 from version 1607 to 22H2, Windows 11 from 23H2 to 26H1, and several Windows Server editions from 2012 through 2025, encompassing both standard and core installations.
Risk and Exploitability
With a CVSS score of 4.3, the vulnerability presents a moderate severity level. Exploitation appears to require network interaction with the Snipping Tool, as indicated by the reference to spoofing over a network; this attack vector is inferred from the description. Detailed EPSS data is not available, and it is not catalogued in the CISA KEV list, suggesting that widespread exploitation has not yet been observed. Nevertheless, the exposure of sensitive data justifies prompt remediation.
OpenCVE Enrichment