Impact
This vulnerability is an out‑of‑bounds read in the Windows kernel that allows an authorized local attacker to bypass a protected security feature. The flaw is a typical memory safety error classified under CWE‑125, enabling the attacker to read data outside the intended bounds of a buffer.
Affected Systems
The flaw impacts a broad range of Microsoft Windows platforms, including Windows 10 versions 1607, 1809, 21 H2, and 22 H2; Windows 11 versions 24 H2, 25 H2, and 26 H1; and Windows Server editions from Server 2012 through Server 2025, both core and standard installations.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1 % shows a very low likelihood of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalogue. Because the attack requires local authentication, a credentialed attacker could bypass the kernel‑level security mechanism, but remote exploitation is not supported.
OpenCVE Enrichment