Impact
A flaw in Windows Cryptographic Services, identified as CWE‑200 (Information Exposure), enables a local attacker with legitimate privileges to disclose sensitive information that should remain confidential. The vendor’s description indicates that the vulnerability allows an authorized user to retrieve data locally, potentially exposing private system information. This type of exposure poses a risk to confidentiality for the affected machine, as the attacker can gather information that could be used in further attacks when combined with other privileges.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core variants) are impacted by this data leakage flaw.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity for a local information disclosure, and the EPSS score of less than 1% reflects a very low probability of exploitation at this time. This vulnerability is not listed in CISA’s KEV catalog, further suggesting limited active exploitation. The likely attack vector is inferred to be local, requiring the attacker to have authorized access; there is no evidence of remote or web-based exploitation paths in the current description.
OpenCVE Enrichment