Impact
A flaw in the Windows Media component exposes sensitive internal data to an unauthorized actor, permitting local disclosure of information that should remain confidential. The vulnerability is classified as a CWE-200 information disclosure weakness, indicating that improper handling of private data is occurring. The exploit does not grant remote code execution or elevate privileges; it simply lets an attacker with local access read sensitive data, which could include configuration files, user information, or other protected contents.
Affected Systems
Affected systems are Microsoft Windows 10 releases from version 1607 through 22H2, Windows 11 releases from 24H2 through 26H1, and Windows Server editions from 2012 R2 to 2025, in both full and core installations. All impacted operating systems run the default Windows Media runtime components that parse media files, which contain the vulnerable logic.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, reflecting local information disclosure. The EPSS score of < 1% shows a low probability of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: an adversary must already have legitimate local access or coerce a user into opening a malicious media file to trigger the disclosure. No special privileges or remote connectivity are required, but the data accessed may support subsequent attacks.
OpenCVE Enrichment