Impact
The vulnerability is caused by a use of an uninitialized resource within the library (upnp.dll). When exploited, the flaw permits a locally authorized attacker to read memory that has not been properly cleared details or other data that may exist in the process address space. The impact is not remote; it requires the attacker, but the information disclosed can be valuable for further attacks or privacy breaches.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including core installations). The flaw resides in the Universal Plug and Play component upnp.dll, which is present in all listed releases.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity. The EPSS score is reported as less than 1 %, suggesting the probability of exploitation is very low; the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local privileged; the attacker needs to be able to execute code on the target machine, such as having an administrative or otherwise authorized user account. Successful exploitation would unwritten memory, potentially exposing confidential data. Because the flaw relies on an uninitialized resource, the attacker does not need to send crafted traffic over the network, making the requirement for remote exploitation unlikely.
OpenCVE Enrichment