Impact
An untrusted pointer dereference in the Windows Graphical Device Interface allows a local, authorized attacker to read memory and thereby discloses sensitive information. The vulnerability is a local privilege exploitation that can compromise confidentiality of data stored in memory. The weakness corresponds to CWE-822, which describes local information disclosure through improper handling of pointers.
Affected Systems
Microsoft Windows operating systems are affected. This includes the Windows 10 family (versions 1607, 1809, 21H2, and 22H2), the Windows 11 family (versions 23H2, 24H2, 25H2, and 26H1), as well as Windows Server releases from 2012 through 2025, including both full and Core installations. The affected platforms span 32‑bit, 64‑bit, and ARM64 architectures as indicated by the CPE data.
Risk and Exploitability
The CVSS score of 5.5 points to moderate severity; the EPSS score below 1% indicates a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must be operating locally with authorized access, and the flaw does not provide a remote code execution path. Consequently, the threat level is moderate for affected systems but remains limited by the local nature of the attack and the limited exploitation likelihood.
OpenCVE Enrichment