Impact
A protection mechanism failure in Windows Event Logging Service permits an authorized attacker to disclose system event data over the network. The vulnerability, identified as CWE‑693, enables the attacker to gain information about system configuration, operations or potentially sensitive log content, without altering system state or executing code. The impact is confined to the confidentiality of the disclosed information, with no known denial of service or intrusion persistence.
Affected Systems
The flaw affects several Microsoft Windows releases including Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2019, Server 2022, and Server 2025, both full and core installations.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1 % suggests a very low likelihood of exploitation at present. Since KEV lists the vulnerability as not currently exploited, the overall risk remains moderate. The attack requires an attacker to have authorized access, but the input does not specify whether this access is local or remote; it is inferred that local privileged access is the likely scenario to trigger the event log transmission over the network. No remote exploitation vector is documented, and no public exploit code is known.
OpenCVE Enrichment