Impact
Uninitialized resources in the Windows SMB service permit an authorized attacker to read data that should not be exposed, resulting in unintended information disclosure. The flaw is classified as CWE-908 and compromises the confidentiality of data stored on affected systems.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025—including the Server Core installations—are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 places the flaw in the medium severity category. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must have local authorized access to any of the affected systems, as the description states that disclosure is local and requires authorized access.
OpenCVE Enrichment