Impact
The issue resides in the Win32K kernel component of Windows, allowing an attacker who already has local authorized access to read sensitive data from the system. This is a CWE-200 information disclosure vulnerability. Based on the description, it is inferred that no remote exploitation path exists and that the disclosed information is limited to what is already within the local user’s scope. The flaw does not grant code execution or privilege escalation, but it can expose confidential material such as memory contents or cached data held by the operating system.
Affected Systems
Microsoft Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 26H1, Windows Server 2022, Windows Server 2025, and Windows Server 2025 (Server Core installations).
Risk and Exploitability
The CVSS score of 5.5 signals moderate severity, while the EPSS score of 0.00458 (less than 1%) indicates that exploitation attempts are currently very low. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Exploitability requires that an adversary already have legitimate local access or code execution privileges on the affected operating system edition. Consequently, the risk is confined to environments where local access is possible; mitigating the flaw remains prudent as the impact, although moderate, can compromise confidential information.
OpenCVE Enrichment