Impact
The AppID subsystem flaw permits an attacker who has local authorized access to read sensitive data that it stores, such as credentials or tokens, thereby exposing confidential information. This is a classic information‑disclosure weakness classified as CWE‑200.
Affected Systems
Affected are multiple Microsoft Windows client and server releases, including Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, the duplicate 23H2 variant, and the corresponding Server editions: Windows Server 2016 (standard and Server Core), Windows Server 2019 (standard and Server Core), Windows Server 2022, and Windows Server 2025 (standard and Server Core).
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Attack requires local authorized privileges; there is no remote execution or privilege escalation vector. The impact is confined to disclosure of sensitive data within the AppID subsystem.
OpenCVE Enrichment