Impact
The vulnerability is an out‑of‑bounds read in the NTFS file system driver. An attacker who has local authorization can trigger the read, leaking arbitrary data from memory. Because the data may contain sensitive information such as credentials or encryption keys, the consequence is local information disclosure, compromising confidentiality on the affected machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012 (standard and core), 2012 R2, 2016, 2019, 2022, and 2025 (including core installations).
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1 % shows a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Because the attacker must be authorized locally, the impact is confined to the user’s session and does not provide remote access, but the local disclosure of sensitive data still poses business risk.
OpenCVE Enrichment