Impact
An authorized local attacker can exploit a flaw in Windows Universal Plug and Play (UPnP) Device Host to view private personal information. The vulnerability is classified as an information exposure weakness, which allows the attacker to read data that should be protected by the system. Because the exploitation does not require additional privileges beyond local authorization, the damage is limited to the information accessible to the attacker, such as user names, device information, or other personal data stored on the affected system.
Affected Systems
The flaw affects a wide range of Microsoft Windows operating systems: Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, including both standard and Server Core installations. All listed platforms with the corresponding architecture variants are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity impact. Because the exploit requires local authorization, the EPSS score is not available, but the vulnerability is not listed in CISA’s KEV catalog. Therefore, while the likelihood of widespread exploitation is modest, any attacker who gains local access to a machine running the affected versions could obtain sensitive personal data. The recommended approach is to treat this as a medium-risk disclosure that should be mitigated promptly by applying vendor updates.
OpenCVE Enrichment