Impact
The vulnerability arises from an out‑of‑bounds read in Windows Print Spooler components, classified as CWE‑125. It allows a local attacker with sufficient privileges to read memory beyond intended bounds and leak sensitive data from the affected system. The disclosure is limited to information accessible on the compromised host and does not provide remote access or other capabilities.
Affected Systems
Affected Microsoft products include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server versions 2012, 2012 R2, 2016, 2019, 2022, and 2025, both full and server‑core installations. All affect the Print Spooler service.
Risk and Exploitability
The CVSS score of 5.5 labels the vulnerability as moderate. The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exfiltration is possible only by a local user with adequate need to be logged on or have injected code into a local process. The attack vector is local and requires successful exploitation of the out‑of‑bounds read to read memory containing potentially sensitive information.
OpenCVE Enrichment