Impact
A memory corruption flaw in the Windows Application Identity (AppID) Subsystem permits an attacker with local authorized access to perform an out‑of‑bounds read, leaking data that may reside in memory. The vulnerability is classified as an out‑of‑bounds read (CWE‑125), which can expose sensitive information such as credentials, tokens, or user data. The impact is limited to confidentiality loss for the local user session and does not enable local privilege escalation or remote code execution.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1 as well as Microsoft Windows Server 2025, including the Server Core installation. The affected platforms are documented by Microsoft’s Windows update guide.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits. The likely attack vector requires the attacker to be an authorized user on the target machine, from which the out‑of‑bounds read may expose memory contents. Because the flaw only reads data locally, the risk is confined to the compromised account and does not spread beyond the host.
OpenCVE Enrichment