Impact
An error message produced by Microsoft COM for Windows contains sensitive data, allowing an authorized local attacker to read confidential information. The issue is limited to information disclosure; no integrity or availability impact is described.
Affected Systems
Affected are Microsoft Windows 10 1809, 21H2, 22H2, Windows 11 23H2, 24H2, 25H2, 26H1 and Windows Server 2019, 2022 and 2025, in all CPU architectures listed by the C‑PE strings.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, and the EPSS score is not available, suggesting little known exploitation activity. The vulnerability is not listed in CISA’s KEV catalog. An attacker must be locally authorized and able to trigger the COM component to generate the error; no remote execution or privilege escalation is required.
OpenCVE Enrichment