Impact
An authorized attacker on a Windows system can exploit a weakness in Windows Cryptographic Services that allows the disclosure of sensitive data to an unauthorized actor. The flaw is a classic information‑disclosure vulnerability (CWE‑200) that permits local read access to data that should remain protected.
Affected Systems
Microsoft Windows 10 builds 1607, 1809, 21H2 and 22H2, Microsoft Windows 11 builds 24H2, 25H2 and 26H1, as well as Windows Server editions 2016, 2019, 2022 and 2025, including their Server Core installations, are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and the attack vector is local, requiring the attacker to have authorized but potentially limited privileges on the compromised host. Consequently, the risk is contained to local data exposure rather than remote compromise or denial of service.
OpenCVE Enrichment