Impact
A flaw in the Active Directory Federation Services component of Windows 11 allows an out‑of‑bounds read that could expose sensitive information to an attacker with legitimate credentials. The defect is described as a memory safety issue (CWE‑125) that permits disclosure of confidential data over the network, potentially violating confidentiality without compromising integrity or availability. If exploited, the attacker could obtain sensitive system state information that may aid in further intrusions.
Affected Systems
Microsoft Windows 11 version 26H1 is the only product explicitly identified as vulnerable. The issue resides within the A.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating a high severity, but its EPSS score is below 1 %, pointing to a low probability of widespread exploitation. It is not listed in the CISA KEV catalog. The attack requires an attacker who already holds authorized access to the environment, as the out‑of‑bounds read can only be triggered from within the ADFS process. The impact is limited to information disclosure rather than code execution or denial of service.
OpenCVE Enrichment