Impact
An out‑of‑bounds read flaw in the Windows Encrypting File System (EFS) allows an authorized attacker with local access to read unintended data from memory, revealing information stored on the local system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attack vectors are local; an attacker must have authorized or administrative access to leverage the out‑of‑bounds read and expose data on the compromised system. Given the local nature of the vulnerability and the low EPSS score, the overall risk is moderate, and mitigation is recommended to prevent information disclosure.
OpenCVE Enrichment