Impact
The vulnerability is an out‑of‑bounds read in Microsoft UxTheme Library (uxtheme.dll). An attacker with local authorized privileges can exploit this flaw to trigger a denial of service on the affected system. The weakness corresponds to CWE‑125, an out‑of‑bounds read that may lead to application instability or crash.
Affected Systems
Affected products include Microsoft Windows 10 build 1607, 1809, 21H2, and 22H2, Microsoft Windows 11 builds 23H2, 24H2, 25H2, and 26H1, and several Windows Server editions such as 2012, 2012 R2, 2016, 2019, 2022, and 2025. Both client and server core installations are impacted.
Risk and Exploitability
The CVSS score of 5.5 places this vulnerability at moderate risk. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local and requires an authorized user to execute theme‑related operations. Because the flaw causes a crash, it can interrupt user sessions but does not lead to data loss or privilege escalation.
OpenCVE Enrichment