Impact
The vulnerability stems from an uninitialized resource in the Windows Imaging Component, permitting a local attacker with authorized privileges to read sensitive data that should remain concealed. This flaw falls under CWE‑908, exposing information via an uninitialized resource. The potential impact is a breach of confidentiality for data stored or processed by the imaging component, but it does not affect integrity or availability.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2 and 22H2, Windows 11 releases 23H2, 24H2, 25H2, 26H1, Windows Server 2012 (standard and Core), Windows Server 2012 R2 (standard and Core), Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025 (all builds). Systems running the Windows Imaging Component in any of these operating system builds are vulnerable unless patched.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% shows that professional exploitation is considered very unlikely at this time. Because the flaw requires local, authorized user access and is not publicly exploitable remotely, the overall risk is limited but not negligible. The vulnerability is not yet listed in the CISA KEV catalog, further reducing concern about widespread active exploitation, yet administrators should still prioritize applying the vendor patch to eliminate the data disclosure vector.
OpenCVE Enrichment