Impact
The vulnerability stems from the use of an uninitialized resource in the Windows Event Logging Service, enabling an authorized local attacker to read data that should remain private. The result is the leakage of sensitive information that could include log entries, configuration details, or other privileged data. This flaw does not allow remote code execution or denial of service, but the disclosed data could aid in further credential‑related attacks or system reconnaissance.
Affected Systems
Affected systems span a wide range of Microsoft Windows client and server editions. Client releases include Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1. Server releases include Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Server Core installations). All affected operating system versions are enumerated in the Microsoft advisory.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, while the EPSS score of less than 1% shows a low probability of exploitation. The flaw is exploitable only by an individual who already has local authorization—an attacker would need to run a program that interacts with the event logging service to trigger the read of uninitialized memory. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread or active exploitation has been observed.
OpenCVE Enrichment