Impact
A flaw in the Windows Graphics Component permits an attacker who is already logged into the system to read sensitive data that should not be exposed. This results in local information disclosure. The vulnerability is classified with CWE‑200, indicating it is an information disclosure weakness. As the CVE description states that the disclosure can be triggered by an authorized attacker, it is inferred that the attacker must have local user credentials to exercise this vulnerability.
Affected Systems
Affected systems include Microsoft Windows 11 releases 24H2, 25H2, 26H1 and Windows Server 2025, including Server Core installations. The flaw resides in the graphics runtime component present in these operating system builds.
Risk and Exploitability
The CVSS base score of 5.5 indicates a medium severity issue, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, further implying limited observed exploitation. It is inferred that the attack vector is local authentication, meaning that threat actors must already have legitimate access to the machine to extract data. Although a single compromised account can leak valuable information that may aid further attacks, the overall attack surface remains confined to authorized users.
OpenCVE Enrichment