Impact
The vulnerability allows an attacker who already has legitimate local access to Windows Media to read sensitive data that should remain hidden. This is an Information Exposure flaw (CWE‑200) that exposes confidential information that could be used to compromise user privacy or gain additional footholds within the system. No remote exploitation path is described; the impact is limited to local systems where the attacker is present.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025 across all supported CPU architectures. The issue applies to both full installations and Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, and the EPSS score of less than 1% shows a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a local authenticated attacker, who can leverage authorized privileges to trigger the information disclosure as described in the description.
OpenCVE Enrichment