Impact
The vulnerability is an out‑of‑bounds read inside Microsoft Standard XPS that permits an authorized local attacker to disclose information that should remain confidential. The weakness falls under CWE‑125 and allows a local user with sufficient privileges to read data beyond the intended buffer boundary, potentially leaking sensitive content from memory. The impact is limited to confidentiality: a local attacker can extract portions of memory that may contain passwords, cryptographic keys, or other confidential data, but the vulnerability does not provide direct code execution or privilege escalation. Based solely on the CVE description, there is no mention of denial of service, authentication bypass, or remote execution, so the primary consequence is data disclosure.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 categorizes the risk as moderate; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring the attacker to be authenticated or to have authorization on the affected machine. Because the flaw is an out‑of‑bounds read rather than an execution flaw, exploitation is less likely to have catastrophic system‑wide effects, yet it still poses a significant risk in environments where sensitive data resides in memory accessible to the XPS subsystem. Given that the exploit can only be achieved on systems with the affected Windows or Server versions and that only a patch removes the vulnerability, the overall threat remains moderate but warrants timely remediation.
OpenCVE Enrichment