Impact
This vulnerability is caused by the use of an uninitialized resource in Windows GDI+. An attacker who has authorized local access can read data that was not properly initialized by the system, resulting in the disclosure of sensitive information stored in memory. The flaw does not allow for privilege escalation or remote exploitation, but it does compromise the confidentiality of data on the affected machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including all Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 classifies the vulnerability as moderate, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild at this time. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited exploitation activity. An attacker would need local authenticated access to the affected system to read the memory contents exposed by the uninitialized resource, and the flaw does not enable remote code execution or elevation of privileges.
OpenCVE Enrichment