Impact
A buffer over-read bug in the Windows Win32K subsystem permits a local user with sufficient privileges to read memory that the process should not access. The flaw occurs through improper bounds checking and allows the attacker to disclose potentially sensitive data. The vulnerability is classified as CWE‑126. The result is a loss of confidentiality for information residing in the affected process’s address space; integrity or availability are not impacted and the exploitation is confined to the local machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, all editions. The flaw exists in both client and server builds, including Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 places the flaw in the moderate range, and an EPSS score of less than 1% indicates a very low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to be able to execute code locally with sufficient privileges that can interact with the Win32K subsystem, such as an authenticated local user or a compromised account. No remote entry vector or privilege escalation is required for exploitation.
OpenCVE Enrichment