Impact
The vulnerability is an out-of-bounds read in the Windows TCP/IP stack that permits a local, authorized attacker to read arbitrary memory addresses within the kernel. This can expose sensitive data such as passwords, cryptographic keys, or configuration information, thereby compromising the confidentiality of the affected system. The flaw is classified as CWE-125.
Affected Systems
This issue affects Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 24H2, 25H2 and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022 and 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS base score of 5.5 designates the vulnerability as medium severity, while the EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires local authorized access, such as that granted to an administrator or a compromised user account. The out-of-bounds read could be triggered by kernel or user-mode components that interact with the network stack.
OpenCVE Enrichment