Impact
This vulnerability in Windows Audio Service permits an attacker who already has local authorized access to read sensitive information that should otherwise be protected, representing a failure to adequately control confidentiality (CWE‑200).
Affected Systems
Affected systems include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server versions 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 classifies this flaw as moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. Because the flaw requires an attacker to already possess authorized local access, the risk is limited to local scenarios; the vulnerability is not listed in CISA’s KEV catalog, so no active exploits are known.
OpenCVE Enrichment