Impact
The flaw in Windows DirectX allows an unauthorized local attacker to read sensitive data that should remain protected. This information‑disclosure vulnerability (CWE‑200) can expose confidential information stored within DirectX components, jeopardizing the privacy of the host system's users and potentially revealing configuration or credential data.
Affected Systems
The impacted products include Microsoft Windows 10 (Version 1809, 21H2, 22H2), Microsoft Windows 11 (Version 24H2, 25H2, 26H1), and Microsoft Windows Server 2019, 2022, and 2025, as well as the Server Core installations of 2019 and 2025. All affected builds rely on the DirectX runtime, and the vulnerability can be triggered by any local user with access to the operating system.
Risk and Exploitability
The CVSS score of 6.2 denotes moderate severity, while the EPSS score of less than 1 % indicates a low probability of exploitation in the wild. Because the attack vector is limited to local access and the vulnerability is not listed in CISA’s KEV catalog, the risk remains confined to environments where an attacker can run code locally on an unpatched system.
OpenCVE Enrichment