Impact
The vulnerability originates from an uninitialized resource within Microsoft Account, which allows an authorized local attacker to read information that should be protected. The flaw is classified as an information exposure weakness (CWE-200) and involves improper resource handling (CWE-908). The CVE description does not specify the exact type of data exposed, so it is inferred that sensitive account information could be revealed, but the presence of credentials or other secrets is not explicitly stated.
Affected Systems
This issue affects multiple Microsoft Windows product lines. It is present in Windows 10 releases from 1607 to 22H2, Windows 11 releases from 23H2 through 26H1, and various Windows Server editions including 2012, 2012 R2, 2016, 2019, 2022, and 2025, both regular and Server Core installations. Users of any of these operating systems may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate risk. The vulnerability requires local authorization; remote exploitation is not possible. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog. Given the moderate severity and potential confidential data exposure, timely remediation is advised.
OpenCVE Enrichment