Impact
An uninitialized resource within the Windows SMB stack allows an authorized local user to read data that should remain protected, resulting in a confidentiality breach. The vulnerability is caused by a flaw that leaks memory contents inadvertently exposed by the SMB protocol handling. The potential impact is the disclosure of private data on the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21 H2, 22 H2, Windows 11 versions 24 H2, 25 H2, 26 H1, and all supported Windows Server releases (2012, 2012 R2, 2016, 2019, 2022, 2025), including Server Core editions and the processor architectures represented in the listed CPEs.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The flaw requires an authorized local user to trigger the disclosure; remote exploitation is not possible. The vulnerability is not catalogued in the CISA KEV list.
OpenCVE Enrichment