Impact
The flaw is a buffer over-read in the Windows Kernel that permits a local attacker who has authorized access to read memory beyond intended bounds. The over-read can reveal sensitive contents from kernel buffers, which may include system secrets or state that could aid future attacks. The weakness is classified as a classic unbounded read, mapped to CWE-126.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025—including Server Core installations.
Risk and Exploitability
The CVSS base score is 5.5, which places the vulnerability in a moderate severity range. EPSS is reported as less than 1%, indicating a very low probability of exploitation in the wild. It is not present in CISA’s KEV catalog. Based on the description, it is inferred that the vulnerability does not provide remote code execution or privilege escalation. The attack requires local, authorized interaction and does not provide remote compromise. However, exposure of kernel memory could serve as a stepping stone for privileged attackers to conduct further exploitation.
OpenCVE Enrichment