Impact
The flaw is an improper link resolution before file access in the Universal Plug and Play library (upnp.dll). A local user with authorized access can exploit this to read files referenced through symbolic links, exposing sensitive configuration or system files. The weakness is identified as CWE‑59.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, including both full and Server Core installations. These builds run on x86, x64, and arm64 architectures as indicated by the CPE data.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity for the vulnerability. Combined with an EPSS score of less than 1%, the likelihood of exploitation during the advisory window is considered low. The vulnerability is not listed in CISA KEV. An attacker must first have legitimate local access to the system; remote exploitation is not possible. Consequently, the risk is confined to the confidentiality of locally logged‑in users, and no broader system or network compromise can be achieved.
OpenCVE Enrichment