Impact
An out-of-bounds read flaw in the Windows Win32K graphics subsystem allows an authorized local user to read memory outside of bounds, which can be leveraged by an attacker to increase privileges on the host. The weakness is a classic out-of-bounds read (CWE‑125) and enables an attacker to compromise confidentiality, integrity, and availability of the affected system by gaining higher privilege levels. No remote exploitation is disclosed; the vulnerability requires local user execution to be exploited.
Affected Systems
The flaw affects multiple Microsoft Windows editions, including Windows 10 from version 1607 through 22H2, Windows 11 from versions 23H2 through 26H1, and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both full and server‑core installations). All affected builds listed in the CNA vendor/product data are vulnerable until the vendor applies a fix.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity. EPSS data is currently unavailable, and the flaw is not yet present in the CISA KEV catalog. The likely attack vector is local, requiring an authenticated or authorized user to trigger the vulnerable Win32K code. Once triggered, the attacker could elevate local privileges, potentially taking full control of the machine. The absence of a publicly known remote exploitation technique reduces the overall exposure, but the local nature combined with high severity warrants immediate remediation.
OpenCVE Enrichment