Impact
The Windows Trusted Runtime Interface Driver contains an information disclosure flaw that allows an attacker with local system authorization to read sensitive data through the driver interface. The exploit results in confidentiality compromise, consistent with CWE-200, and does not affect integrity or availability.
Affected Systems
Affected operating systems are Microsoft Windows 10 21H2, Windows 10 22H2, Windows 11 24H2, 25H2, 26H1, and Windows Server 2025 (both standard and Server Core installations). The vulnerability spans x86, x64, and arm64 architectures, as reflected in the provided CPE data.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate impact. The EPSS score of less than 1% shows a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring an authorized user or a privileged attacker, an inference made from the description rather than explicit statement. Prompt patching eliminates the disclosure risk.
OpenCVE Enrichment