Impact
The vulnerability is a use‑after‑free in Microsoft QUIC that permits an unauthenticated attacker to read data that should not be accessible over the network. The flaw results in a breach of confidentiality where sensitive information may be exposed. The weakness is classified as CWE‑416, a classic use‑after‑free bug.
Affected Systems
Affected products include Microsoft .NET versions 8.0, 9.0, and 10.0, as well as Microsoft Visual Studio 2022 release 17.14 and Microsoft Visual Studio 2026 release 18.8. All listed versions are exposed to the information‑disclosure issue.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability, while the EPSS score of 1% suggests that exploitation is unlikely but not impossible. The issue is not listed in CISA KEV. The attack vector is likely remote, as the flaw can be triggered over a network connection to a QUIC endpoint, and only requires an unauthorized attacker to send crafted traffic to elicit the memory read.
OpenCVE Enrichment
Github GHSA