Impact
Out-of-bounds read in the Win32K graphics subsystem allows an authorized local attacker to read arbitrary memory, potentially exposing sensitive data. The flaw is a classic out‑of‑bounds read (CWE‑125) that does not provide code execution but can leak confidential information to a user on the affected system.
Affected Systems
Microsoft products include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025. The vulnerability exists on both x86 and x64 architectures and on ARM64 variants for Windows 11.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is less than 1 %, suggesting a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. An attacker would need local authorized privileges to exploit the issue, most likely via a malicious or misbehaving application running with those rights. No known public exploit remains available at this time.
OpenCVE Enrichment