Impact
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. Based on the description, it is inferred that an attacker can obtain sensitive information and exfiltrate it over the network. This flaw is classified as CWE-125 and undermines confidentiality without requiring elevated privileges.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025 (both full and Server Core installations). It applies to x86, x64, and ARM64 architectures where available.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level, yet the EPSS score of < 1% suggests a low probability of real-world exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker can trigger the flaw by sending crafted requests to the vulnerable kernel component over the network, making the likely attack vector network‑based from an unauthenticated host.
OpenCVE Enrichment