Impact
The vulnerability is an out-of-bounds read in the Windows Text Shaping component. An attacker who can run code with local user privileges can trigger the read and obtain memory contents that are not normally accessible, leading to disclosure of confidential information. The weakness is classified as CWE‑125.
Affected Systems
The affected systems are Microsoft Windows 10 starting with version 1607 through 22H2 and Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as all core and full installations of Windows Server 2012 through 2025, including the 2016, 2019, 2022, and 2025 releases.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The likely attack vector requires a local attacker with authorized access; therefore the risk is limited to environments where users can execute code locally. While the threat of data leakage exists, the exploitation probability is low without higher privileges or active use of the vulnerable component.
OpenCVE Enrichment