Impact
An out-of-bounds read exists in Windows Management Instrumentation, which can be triggered by a locally authorized user. The flaw allows the attacker to read memory locations beyond the intended buffer, potentially exposing sensitive data such as configuration information, credentials that reside in memory, or other confidential material. The weakness is classified as CWE‑125, a type of unsafe memory access that can disclose information but does not alter the system state or cause denial of service.
Affected Systems
The vulnerability affects a wide range of Microsoft operating systems. End‑users and administrators should check the following: Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both Standard and Server Core installations. These systems include both x86 and x64 architectures as specified in the affected product list.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate impact level, while the EPSS score is reported as less than 1 %, suggesting that the likelihood of exploitation in the wild is extremely low at this time. The flaw requires local privilege to succeed; no remote or network‑based exploitation is reported. The vulnerability is not listed in the CISA KEV catalog, further indicating that active exploitation is not currently known.
OpenCVE Enrichment