Impact
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. The vulnerability stems from a boundary checking flaw in a kernel component, enabling a local exploit that can reveal sensitive data. This is a type of memory corruption weakness (CWE‑125).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, while the EPSS score of <1% suggests a low exploitation probability. The vulnerability is not listed in CISA KEV. Exploitation requires local authorization; remote access is not described. The risk is moderate, so organizations should ensure the flaw is addressed through patching or monitoring.
OpenCVE Enrichment