Impact
The vulnerability arises from an uninitialized resource within Microsoft Windows Codecs Library, allowing an unauthorized local attacker to read sensitive data that is not intended for disclosure. This flaw can expose files, configuration settings, or other memory content, potentially compromising the confidentiality of the affected system.
Affected Systems
Microsoft operating systems from Windows 10 version 1607 through Windows 11 version 26H1 and Windows Server 2012 through Windows Server 2025, including both full and server‑core installations, are affected. The affected platforms span 32‑bit, 64‑bit, and ARM64 architectures across multiple Windows releases.
Risk and Exploitability
The vulnerability has a CVSS score of 5.5, indicating moderate impact. The EPSS score is below 1 %, suggesting a low probability of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. It is a local information‑disclosure flaw, so the attacker requires local access or user‑initiated privilege, and no network‑based exploitation is known. Based on the description, it is inferred that the attack vector involves local execution or exploitation of the codec when loading or processing media files.
OpenCVE Enrichment