Impact
An authorized local attacker can trigger an exposed Win32K interface, causing the Windows kernel to reveal sensitive information. The vulnerability is classified as Information Exposure (CWE‑200). Because execution occurs with the privilege level of the user running the operation, the attacker can only access data that requires the same local authorization, limiting the impact to local confidentiality rather than remote code execution or system-wide compromise.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025 (including Server Core installations).
Risk and Exploitability
The attack vector is local and requires authorized local access. The CVSS score of 3.3 and an EPSS score of less than 1 % indicate low severity and a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, which further reduces the risk surface for most environments.
OpenCVE Enrichment