Impact
An out‑of‑bounds read in the Windows kernel permits an attacker without prior authorization to retrieve sensitive data via a network connection. The vulnerability is a CWE-125 buffer overread combined with a CWE-200 information disclosure weakness, allowing leakage of confidential memory contents. Based on the description, it is inferred that there is no remote code execution or privilege escalation.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, 2022, and 2025, including Server Core installations for 2016, 2019, and 2025.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, yet the EPSS score of less than 1% suggests that active exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. It can be triggered from a remote machine that communicates with the target, allowing the attacker to read kernel data over the network. Based on the description, the principal risk appears to be privacy compromise rather than widespread active attacks.
OpenCVE Enrichment