Impact
Microsoft Trace Data Helper contains an out‑of‑bounds read that can be triggered by an authorized local user. The flaw allows the attacker to read beyond the intended memory boundary, potentially enabling escalation of privileges on the affected system. This vulnerability is a classic memory corruption issue identified as CWE‑125.
Affected Systems
Affected by variants of Windows 11 (V24H2, V25H2 and V26H1) as well as Windows Server 2025, including the Server Core installation. The affected architectures are Arm64 for the Windows 11 V24H2 and V25H2 releases and x64 for V26H1.
Risk and Exploitability
The Microsoft security advisory assigns a CVSS score of 7.8, indicating high severity. EPSS data is not available, so the exact exploitation likelihood cannot be quantified, and the vulnerability is not listed in the CISA KEV catalogue. The attack vector is local; an attacker must have authenticated or otherwise authorized access on the host to exploit the flaw, after which they may gain elevated privileges within that session.
OpenCVE Enrichment