Impact
This vulnerability allows a local authorized attacker to read sensitive information that is normally protected by the Windows kernel. The flaw is an information disclosure flaw (CWE‑200). Because an attacker must already have some local privilege to exercise the vulnerability, the scope is confined to local systems.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2 and Microsoft Windows 11 versions 24H2, 25H2, 26H1, as well as Microsoft Windows Server releases from 2012 to 2025 (including core installations), are affected. All vulnerable editions run on the architectures listed in the CPE data, so both x86 and x64 machines are within reach.
Risk and Exploitability
The CVSS base score of 3.3 indicates a low severity overall, and the EPSS score is less than 1%, suggesting a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalogue. An attacker would need local privilege and the opportunity to trigger the kernel code that leaks data, so the likelihood of a practical exploit is limited unless elevated privileges are already compromised.
OpenCVE Enrichment