Impact
A flaw in Windows Management Instrumentation arises from the use of an uninitialized resource, allowing an attacker who is already authorized to read confidential data over a network. This disclosure can reveal sensitive information that the attacker would normally not have access to, thereby compromising confidentiality. The weakness is identified as CWE-908.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity level; the EPSS score of < 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. The likely attack vector is an authenticated user with network access to a machine running the Windows Management Instrumentation service. No public exploit has been reported, but an attacker could use legitimate credentials to query and extract privileged data across the network.
OpenCVE Enrichment