Impact
An out-of-bounds read flaw exists in the Windows Kernel. An attacker who has local user privilege can trigger the flaw to elevate privileges to SYSTEM level. This is a kernel memory safety issue that compromises the integrity and confidentiality of the operating system. The impact is a local privilege escalation that can give full control over the affected machine.
Affected Systems
Affected are Microsoft Windows 10 releases 1607, 1809, 21H2, 22H2; Windows 11 releases 24H2, 25H2, 26H1; and Windows Server 2016, Server 2016 Core, Server 2019, Server 2019 Core, Server 2022, and Server 2025 (including Core installations). Deployments of these OS variants are susceptible to the kernel read bug.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. The EPSS score of less than 1 percent shows a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need local user access and must drive the kernel to perform the out-of-bounds read. With the limited exploitation potential, organizations should still treat the flaw as a high-value local vulnerability and act promptly if possible.
OpenCVE Enrichment