Impact
The vulnerability in the Windows Overlay Filter permits an authorized local attacker to read sensitive information that should be protected by the operating system. This forms a classic information‑disclosure flaw, classified as CWE‑200, where information that is not meant for public consumption becomes accessible to users who have local access to the system.
Affected Systems
Affected systems include Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, 2022, and 2025, both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk level, while the EPSS score of less than 1% points to a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, and no active exploits are publicly documented. Because the flaw requires an authorized local user, the threat is confined to those with sufficient local privileges, but the potential exposure of sensitive data makes it a noteworthy local risk that should be mitigated promptly.
OpenCVE Enrichment