Impact
BranchCache, a Windows feature that caches shared files over the network, contains an out‑of‑bounds read flaw. An attacker who can target BranchCache can cause the service to crash or become unresponsive, resulting in denial of service for users who depend on BranchCache. The flaw does not grant code execution or arbitrary data disclosure; it simply disrupts the integrity and availability of the caching service.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1) and all major Windows Server releases from 2012 through 2025, including their Server Core images, are affected. Devices that enable BranchCache on any of these operating systems are vulnerable. The CPE matrix confirms broad support across the x86, x64, and ARM64 platforms.
Risk and Exploitability
The advisory lists a CVSS base score of 7.5, indicating a high potential for denial of service. The EPSS score is 1%, and the vulnerability is not currently listed in the CISA KEV catalog, suggesting that exploitation data is not widespread as of the latest assessment. An attacker would need network access to a system that has BranchCache enabled and would craft a malicious request that triggers the out‑of‑bounds read. Because the issue is remotely exploitable over the network, any host exposed to untrusted traffic that uses BranchCache can be affected. While the flaw does not lead to arbitrary code execution, the resulting service disruption could be disruptive for business continuity or user productivity.
OpenCVE Enrichment