Impact
The vulnerability is an out-of-bounds read in the Windows Overlay Filter component, allowing an attacker who has authorized local access to read memory data that should be protected. This leakage can expose sensitive information stored in memory that is accessible to the local process, potentially revealing credentials, cryptographic keys, or other confidential data. The impact is limited to the compromised local environment and does not provide remote code execution or service disruption.
Affected Systems
Affected are multiple Windows operating systems, including Windows 10 build versions 1607, 1809, 21H2, and 22H2; Windows 11 build versions 23H2, 24H2, 25H2, and 26H1; and Windows Server releases 2012 R2, 2016, 2019, 2022, and 2025, for both standard and Core installations.
Risk and Exploitability
The CVSS score of 5.5 categorizes this as moderate severity. Because the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of widespread exploitation is unclear, but the attack vector is inferred to be local with authorized access. An attacker would need to run code in a context that can invoke the Overlay Filter, so the risk is mitigated by limiting privileged access to the affected components.
OpenCVE Enrichment