Impact
The vulnerability is an out‑of‑bounds read in the Windows Desktop Window Manager (DWM) Core Library. An attacker who can execute code on the target machine with authorized local privileges can trigger the read and obtain sensitive data that resides in memory. The weakness is a classic bounds checking failure (CWE‑125). Local attackers can exploit it without remote connectivity and there is no evidence of privilege escalation or denial of service.
Affected Systems
Affected operating systems include Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server versions 2019, 2022, and 2025. The issue applies to both x86 and x64 architectures (including ARM64 on Windows 11).
Risk and Exploitability
The CVSS score is 5.5, reflecting moderate severity. The EPSS score is less than 1 %, indicating low expected exploitation activity, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires local access, attackers would need to be present on the machine or have already obtained local credentials. The out‑of‑bounds read can expose arbitrary memory contents, potentially leaking configuration data or secrets, but the lack of remote access or privilege escalation limits the immediate damage.
OpenCVE Enrichment