Impact
An improperly initialized resource in Microsoft Windows App Store enables an attacker with legitimate access to the machine to read sensitive data stored within the application’s configuration. This flaw does not allow remote code execution or denial of service, but the information exposed can reveal user credentials, application secrets, or other confidential data that could be leveraged to facilitate further attacks against the device or network.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, 2025 (including Server Core installations). All affected releases operate on x86, x64, or ARM64 architectures as applicable.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity local impact. The very low EPSS (<1%) suggests that exploitation is currently unlikely, but the flaw remains valid. The vulnerability is not listed in CISA’s KEV catalog. Because the requirement for exploitation is local authorization, an insider or a compromised user account is required. Attackers do not need elevated privileges or to traverse a network boundary to gain the disclosed information.
OpenCVE Enrichment