Impact
An out‑of‑bounds read occurs in the Windows Graphics Device Interface, allowing an attacker with local authorization to read memory that they should not access. The flaw does not provide direct remote code execution or elevated privileges, but it can leak sensitive data such as passwords, cryptographic keys, or other confidential information from the victim’s process memory. The weakness falls under CWE‑125, reflecting a classic buffer overread scenario.
Affected Systems
The vulnerability impacts several Microsoft operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1, and 23H2/26H1 (ARM64 and x64); and a range of Windows Server releases from 2012 and 2012 R2 to 2025. All affected editions are referenced by the listed vendor and version names, with no additional platform or architecture exclusions noted.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity; the EPSS score of less than 1% suggests the likelihood of public exploitation is low at present, and the vulnerability is not currently listed in CISA’s KEV catalog. It is inferred that an attacker must have local, authorized access to the target machine to trigger the out‑of‑bounds read, as the description identifies a local attacker as the risk factor. No additional prerequisites such as elevated privileges or remote access are stated, and there is no evidence of a publicly available PoC or exploit code.
OpenCVE Enrichment