Impact
A buffer over‑read in the Windows Wired AutoConfig Service can be triggered by an authorized local user. The flaw allows the user to read memory beyond the intended buffer, exposing potentially sensitive information. The weakness is a classic CWE‑126 buffer overread issue that could leak confidential data from the system memory.
Affected Systems
The vulnerability impacts Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases from 2012 through 2025, covering both standard and core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% shows a low probability of exploitation. The flaw requires an authenticated local attacker with sufficient privileges, and it is not listed in the CISA KEV catalog. Consequently, the risk is moderate but limited to systems where users can gain local access.
OpenCVE Enrichment