Impact
The flaw resides in the Windows Quality of Service (QoS) Packet Scheduler and is classified as an information disclosure vulnerability. The official description notes that internal system data can be exposed, but it does not specify the precise type or scope of the information. Given the nature of QoS scheduling data, the exposed information could include system configuration or state of the scheduler, which may aid an attacker in enumerating system details or privilege escalation possibilities.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. No exploitation evidence has been reported. Based on the description, the attack vector is likely local or requires elevated privileges to manipulate QoS scheduler data; however, specific prerequisites are not detailed in the advisory.
OpenCVE Enrichment