Impact
The vulnerability arises from the cleartext transmission of sensitive data within the Windows Ancillary Function Driver for WinSock. An authorized attacker, who has local access, can read this data, resulting in potential leakage of confidential information. This weakness is categorized under CWE-319, which concerns information transmitted insecurely over a public channel. The primary impact is the compromise of confidentiality for data that should otherwise remain protected from local attackers. Affected systems include a wide range of Microsoft Windows operating systems: Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2 (with and without Server Core), 2016, 2019, 2022, and 2025 versions. This extensive coverage means that any device running these OS editions may be vulnerable if the pending update is not applied. The risk assessment, based on the CVSS score of 5.5, indicates moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog, further reducing its immediate threat level. However, local attackers with sufficient privileges could still disclose information, so remediation should not be delayed.
Affected Systems
Microsoft Windows 10 (1607, 1809, 21H2, 22H2), Microsoft Windows 11 (23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations) are affected by the vulnerability.
Risk and Exploitability
The CVSS score of 5.5 places this issue in the medium risk range, while the EPSS score of less than 1% and absence from the KEV catalog indicate a low probability of current exploitation. Attackers would require local, authorized access and would be exploiting the driver's cleartext transmission of data, typical of a local information disclosure scenario. Given the limited exploitation likelihood, the priority for mitigation is to apply the official Microsoft update and assess application use of the driver.
OpenCVE Enrichment