Impact
The vulnerability is an out‑of‑bounds read in the Schannel component of the Windows operating system. An authenticated attacker with network access can send crafted TLS traffic to a target system, allowing the read to expose data that is transmitted over the secure channel. Because the flaw involves reading beyond array boundaries, it may leak sensitive data such as credentials, cryptographic material, or other confidential information, though it does not permit code execution or denial of service.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their core installations. These systems run on x86, x64, and arm64 architectures as specified by the listed CPE strings.
Risk and Exploitability
With a CVSS score of 8.1 the flaw is assessed as high severity. The EPSS score of 1 % indicates that while exploitation is unlikely, it is possible, and the vulnerability is not currently listed in the CISA KEV catalog. The attack requires an authenticated or otherwise authorized user who can initiate TLS traffic toward the victim; the out‑of‑bounds read then reveals portions of that traffic. Consequently, the principal risk is the accidental or purposeful disclosure of proprietary or personal data rather than compromise of the operating system.
OpenCVE Enrichment