Impact
The flaw is an out‑of‑bounds read in the Windows Desktop Window Manager (DWM) core library that allows an attacker with local authorization to trigger an out‑of‑bounds memory read and expose sensitive data stored in process memory. The identified weakness is CWE‑125, representing an attempt to access memory beyond legitimate bounds. The incident could reveal non‑privileged user data or other information resident in the victim’s memory space.
Affected Systems
Affected operating systems include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025, both in full and Server Core installations. The data indicates that systems running the specified architectures (x86, x64, arm64) are vulnerable, as enumerated in the associated CPE strings.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity for an information‑disclosure weakness. The EPSS score is reported as less than 1 %, suggesting that exploitation is not widespread and likely requires a local attacker. The vulnerability is not listed in CISA’s KEV catalog, indicating no known large‑scale exploitation. The attack vector is inferred to require local, authorized user privileges, and the flaw does not provide remote code execution or privilege escalation on its own.
OpenCVE Enrichment