Impact
The vulnerability arises from improper link resolution before file access in the Windows UPnP Device Host. An authorized local user can craft a malicious link that the host follows, causing it to read arbitrary files. This results in information disclosure limited to the local machine and depends on the privileges of the account running the service. The weakness maps to CWE-59 (Link Following) and CWE-269 (Improper Privilege Management).
Affected Systems
Affected systems include various releases of Windows 10, Windows 11, and Windows Server from 2012 through 2025. Specific versions listed as Windows 10 1607, 1809, 21H2, 22H2, Windows 11 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 across both full and server core editions. All these editions run the UPnP Device Host component.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. No EPSS score is provided, and the vulnerability is not in KEV. The attack vector is based on local access with sufficient privileges over the UPnP Device Host service. An attacker must be able to manipulate the device host or supply a crafted link, which generally requires local administrator or the user context under which the service runs. Because the exploitation is local and does not depend on remote network triggers, the risk is confined to environments where the UPnP Device Host is enabled and accessible to end users.
OpenCVE Enrichment