Impact
A flaw exists in the Windows Media component of Microsoft Windows that permits an attacker to read sensitive data that should be protected. The vulnerability is classified as a classic information‑disclosure weakness (CWE‑200). The description states that an unauthorized actor can disclose information over a network, meaning the flaw does not require local privileges or special conditions beyond normal network access. The impact is the unauthorized exposure or leakage of data transmitted or processed by the Windows Media subsystem.
Affected Systems
As detailed by the CNA, the issue affects multiple Windows operating system releases: Windows 10 Build 1809, 21H2, and 22H2; Windows 11 Builds 24H2, 25H2, and 26H1; and Windows Server releases 2019, 2022, and 2025, including both full installations and Server Core editions. All of these releases contain components of the Windows Media framework that provide the exposed path.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity for this information‑disclosure flaw. The EPSS score of less than 1% indicates that current attacker activity against this vulnerability is expected to be very low. The flaw is not listed in the CISA KEV catalog, and no publicly documented exploits are known. Attackers would need network connectivity to a vulnerable system and would likely send crafted media packets or trigger Windows Media service traffic; the exact protocol or service is not specified, so the precise exploitation method is inferred from standard media usage patterns. Given the moderate score and low exploitation probability, this vulnerability is considered a moderate risk in environments where the Windows Media component is exposed to untrusted networks.
OpenCVE Enrichment