Impact
An out‑of‑bounds read has been identified in the Windows Network Policy Server SNMP implementation. This flaw allows an attacker to read data that, potentially revealing credentials, configuration settings, or other confidential content. The weakness is classed as CWE‑125 and results in an information disclosure that can be triggered without local privileges.
Affected Systems
The vulnerability affects Microsoft Windows 10 builds 1607, 1809, 21H2, and 22H2; Windows 11 builds 24H2, 25H2, and 26H1; and Windows Server 2012 (both standard and core), 2012 R2 (both standard and core), 2016, 2019, 2022, and 2025. The flaw exists only in installations that include the Windows Network Policy Server component and have the SNMP service enabled.
Risk and Exploitability
The CVSS score of 7.5 places the flaw in the high‑severity range, while an EPSS score of 1% indicates a low but non‑zero likelihood of exploitation. Based on the description, it is inferred that an attacker can craft SNMP packets to trigger the out‑of‑bounds read and retrieve protected data remotely over the network. The vulnerability can be leveraged without privileged local access and is not currently listed in CISA’s KEV catalog, but the risk remains due to the remote attack vector and the sensitivity of the disclosed information.
OpenCVE Enrichment