Impact
This vulnerability permits a local attacker to access sensitive data in the Windows Win32K subsystem, a CWE‑200 Sensitive Data Exposure flaw, which can then be leveraged to elevate privileges on the affected system. The resulting privilege escalation can compromise confidentiality, integrity, or availability of the host and any data or services managed by the compromised accounts.
Affected Systems
The flaw affects a range of Windows desktop and server operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24 H2, 25 H2, and 26 H1; and Windows Server releases from 2012 through 2025, both full and Server Core installations. Users running any of these editions should verify their systems for exposure.
Risk and Exploitability
The CVSS score of 6.2 indicates medium severity, while the EPSS score of less than 1 % suggests low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access; an attacker must already have login rights or otherwise be able to execute code on the target machine. Although no public exploit is known, the local privilege escalation potential warrants immediate attention.
OpenCVE Enrichment