Impact
The flaw is a weak authentication control in the Windows Search Component that permits a local user with sufficient privileges to read data it should otherwise protect. This vulnerability is limited to the local environment, meaning an attacker must already have authorized access to the machine. While the disclosure does not enable remote compromise or privilege escalation, it can expose confidential files, registry information, or other sensitive data accessible from the host.
Affected Systems
Microsoft Windows 10 version 1607, 1809, 21H2, 22H2, and Windows 11 version 23H2, 24H2, 25H2, 26H1. Also affected are Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, including Core installations. These operating system releases are all impacted as listed by the CNA.
Risk and Exploitability
The CVSS base score is 5.5, indicating moderate severity. EPSS is below 1 %, suggesting a very low exploitation likelihood currently. The vulnerability is not listed in CISA’s KEV catalog, so there is no documented large‑scale exploitation. Exploitation requires an authenticated local user; the attacker cannot leverage remote access or elevate privileges through this issue. Consequently, the threat is confined to local information disclosure on affected machines.
OpenCVE Enrichment