Impact
An uninitialized resource in Windows GDI+ permits an authorized user to read sensitive information from memory. The flaw is a classic information‑exposure weakness identified as CWE-908. Because the attack requires local access, it does not provide remote code execution or denial of service, but it can reveal private data to the attacker. The primary impact is the leakage of confidential data that may otherwise remain protected by least‑privilege controls. Based on the description, it is inferred that the attacker must have local privileges to trigger the vulnerability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012 through 2025, including Server Core installations. All of these systems run the GDI+ rendering library that contains the vulnerability.
Risk and Exploitability
The CVSS score of 5.5 classifies this flaw as moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been observed in the wild at the time of this analysis. The likely attack vector is local, requiring an authorized or privileged user to trigger the uninitialized resource condition. Exploitation may involve running a user‑controlled application that invokes GDI+ operations, leading to disclosure of memory contents. While the design constraints limit the damage to the local machine, the potential for leaking sensitive data still warrants timely remediation.
OpenCVE Enrichment