Impact
The flaw is an out‑of‑bounds read in the Windows Imaging Component. An attacker who has local credentials can read memory that the component should not expose, enabling disclosure of arbitrary data from the local system. The weakness is classified as CWE‑125.
Affected Systems
Differentiated by vendor product and version, the affected entities are Microsoft Windows 10 releases 1607, 1809, 21H2, 22H2; Windows 11 releases 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. It requires local authorization and has no known remote exploitation vector. Therefore, risk is confined to users or services running with elevated privileges on the targeted systems, and exploitation would typically require user interaction or a local foothold.
OpenCVE Enrichment