Impact
The flaw arises from the use of an uninitialized resource in the Windows SMB stack. An attacker who is already authorized on the local system can read sensitive data from the SMB service, exposing internal information. The vulnerability does not allow code execution or remote compromise; it is purely an information‑disclosure issue tied to CWE‑908.
Affected Systems
Affected platforms include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations for all Windows Server 2012, 2012 R2, 2016, 2019, and 2025 families.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate impact, while the EPSS score of less than 1 % denotes an unlikely exploitation in the wild. Because the flaw requires a locally authorized user, the risk is confined to environments where privileged accounts have SMB access, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment