Impact
An untrusted pointer dereference exists in the Win32K graphics kernel component that allows a local attacker with sufficient privileges to read memory that it should not. This flaw is categorized as CWE-822 and can lead to the disclosure of sensitive data resident in the Windows process address space.
Affected Systems
The flaw affects Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 and the associated arm64 or x64 builds, as well as Windows Server 2025 and its Server Core installation. These operating systems are listed in official advisories from Microsoft.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity impact. The EPSS score of less than 1% suggests that exploitation is considered unlikely at this time, and the vulnerability is not currently flagged in CISA’s KEV catalog. Attackers would need local system or higher level privileges to trigger the vulnerable Win32K functionality, making the attack vector local and authorized. Once the pointer dereference is achieved, the attacker may read protected memory, potentially leaking confidential information.
OpenCVE Enrichment