Impact
An out‑of‑bounds read in the Windows Network Policy Server SNMP component can allow an attacker to read memory contents over a network, potentially revealing sensitive data. This flaw is a classic memory corruption vulnerability (CWE‑125) and does not enable code execution, but it can leak confidential information if exploited.
Affected Systems
Affected platforms include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 24H2, 25H2, 26H1; and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 in both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity flaw, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The description states that an unauthorized attacker can disclose information over the network, implying that no user credentials are required and that the attack can be performed remotely. However, the specific network service or port used for the exploit is not detailed in the available data, so the exact attack vector cannot be definitively stated. Nevertheless, the combination of a high severity rating with a low probability of exploitation indicates that while the risk is moderate, the potential impact on confidentiality warrants prompt attention.
OpenCVE Enrichment