Impact
Microsoft's COM implementation for Windows contains an uninitialized resource that can allow a local user with sufficient privileges to read sensitive memory contents. The flaw is a type of memory corruption (CWE‑908) which results in information disclosure when the vulnerable COM component is invoked. An attacker only needs local access and the ability to instantiate the offending component; no network exposure is required.
Affected Systems
The vulnerability affects a wide range of Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025. Both client and server builds, as well as client‑only and server‑core installations, are listed as vulnerable. Users should verify the specific build, architecture (x86, x64, or arm64), and whether they are running a client or server edition.
Risk and Exploitability
With a CVSS score of 5.5 the threat is moderate. The EPSS score of less than 1 % indicates that publicly documented exploitation is expected to be rare, and the vulnerability is not currently referenced in CISA’s KEV catalog. The attack requires local authorized access; therefore, it should be mitigated against privileged accounts that can instantiate the vulnerable COM component. Because it is a memory‑corruption flaw, exploitation could lead to disclosure of arbitrary information from the victim’s address space.
OpenCVE Enrichment