Impact
A buffer over‐read flaw in the Windows Overlay Filter allows an authorized user to read memory beyond the bounds of a buffer, causing local disclosure of information that may include sensitive data. The weakness is a classic Buffer Overread (CWE‑126) and can potentially expose arbitrary memory contents to an attacker with local access.
Affected Systems
Affected by this vulnerability are multiple Microsoft Windows products, including Windows 10 in versions 1607, 1809, 21H2, and 22H2; Windows 11 in versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, 2022, and 2025, each in its respective standard build, for both the Server Core and full installation options.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate severity level, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires local, authorized access and there is no available EPSS score, the probability of exploitation is likely low, but local attackers could leverage this flaw to gain additional information within the scope of their user privileges. No publicly available exploits or workarounds have been documented, so the primary concern is the potential for increased opportunistic information leakage on compromised or unauthorized machines.
OpenCVE Enrichment