Impact
An out‑of‑bounds read in the Windows DWM Core Library allows a local, authorized attacker to read arbitrary memory, exposing sensitive data on the infected machine. The flaw is a classic buffer underrun that can reveal confidential information without affecting the system’s stability or causing denial of service.
Affected Systems
The vulnerability affects Windows 11 version 24H2, 25H2, and 26H1, as well as Windows Server 2025 and its Server Core installation. All versions are referenced by Microsoft in the advisory, indicating that any copy of these releases is potentially exposed.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate impact. No EPSS value is available, so the likelihood of exploitation in the wild is uncertain. The flaw is not listed in CISA KEV catalog, suggesting there is no known active exploitation. The attack vector is local; an attacker must have user or elevated privileges on the target machine to trigger the read.
OpenCVE Enrichment