Impact
An out‑of‑bounds read bug in the Windows Win32 kernel component, Win32K, allows an attacker who already has local access to read memory beyond the bounds of a buffer. The fault can be exploited to manipulate data or gain escalated privileges, enabling the attacker to obtain higher local system rights. This vulnerability is classified as CWE‑125.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including their Server Core editions. Affected architectures include x86, x64 and arm64 for the respective product releases.
Risk and Exploitability
The CVSS score of 7.8 places this vulnerability in the high severity range, and the EPSS score is not available, so the current exploitation probability is unknown. The flaw is not listed in CISA KEV, implying no confirmed large‑scale exploitation so far. The attack requires local, authenticated access—any privileged user or malware already running on the machine can trigger the bug and raise privileges. Because the flaw is an out‑of‑bounds read, successful exploitation may lead to memory corruption that allows the adversary to bypass security boundaries.
OpenCVE Enrichment