Impact
Windows Program Compatibility Assistant Service contains an out-of-bounds read that permits an authorized attacker to read sensitive data from memory and return it over a network. The vulnerability is a buffer under-read (CWE-125), enabling unauthorized disclosure of confidential information. Because the read occurs in a privileged system service, the attacker must already have a level of authorization within the host environment or rely on local execution privileges.
Affected Systems
Affected systems include Microsoft Windows 10 build 1607, 1809, 21H2, 22H2, Windows 11 build 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core installations.
Risk and Exploitability
CVSS score is 5.7, indicating moderate severity. EPSS is not available, so the current likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely local or requires some pre‑existing authorization; an attacker able to communicate with the system over a network can trigger the read and capture the disclosed data.
OpenCVE Enrichment