Impact
The flaw is an out‐of‐bounds read in the Windows Cloud Files Mini Filter Driver. When a locally authenticated user can exercise the vulnerability, the driver reads memory beyond the intended boundary, allowing the local attacker to view data that should remain protected. The primary impact is the disclosure of information on the affected machine and the vulnerability is categorized as CWE‑125.
Affected Systems
Affected systems include Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2019 (including Server Core), Windows Server 2022, and Windows Server 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 5.5 characterizes this vulnerability as moderate in severity. The EPSS score of less than 1% indicates a very low likelihood of active exploitation at present. Since the bug requires local, authenticated access and offers no remote code execution or privilege escalation, the risk is limited to the local system’s data exposure. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment