Impact
A buffer over-read in the Windows Event Logging Service can be triggered by an authorized local user, leading to disclosure of sensitive information on the target machine. The flaw is classified as CWE‑126 and allows the attacker to read data beyond the intended buffer boundaries, compromising the confidentiality of local data streams.
Affected Systems
The vulnerability affects multiple Microsoft Windows platforms, including Windows 10 Version 1607, 1809, 21H2, and 22H2; Windows 11 Versions 23H2, 24H2, 25H2, and 26H1; and a range of Windows Server releases from 2012 through 2025, including Server Core installations of 2012, 2012 R2, 2016, 2019, 2022, and 2025.
Risk and Exploitability
With a CVSS score of 5.5, the flaw is of moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack is local and requires an authorized user with sufficient permissions to interact with the Event Logging Service. Successful exploitation would primarily affect the confidentiality of local information; availability or integrity impacts are not indicated by the description.
OpenCVE Enrichment