Impact
The vulnerability is an out‑of‑bounds read in the Microsoft Standard XPS subsystem that allows a local, authorized attacker to read restricted data from memory. Because it exploits a classic buffer overrun (CWE‑125), the attacker can potentially obtain sensitive information, such as credentials, configuration data, or other memory contents. The impact is limited to local disclosure and does not provide remote code execution or privilege escalation.
Affected Systems
Affected are Microsoft Windows 10 (Version 1607, 1809, 21H2, 22H2), Windows 11 (Version 23H2, 24H2, 25H2, 26H1), and Windows Server (2012, 2012 R2, 2016, 2019, 2022, 2025 in both standard and server core installations).
Risk and Exploitability
The platform presents a modest CVSS score of 5.5, indicating moderate severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The likely attack vector is local; the attacker must be authenticated with sufficient permissions to trigger the XPS feature, after which the out‑of‑bounds read can be leveraged to disclose information. Without a known exploit or higher EPSS, the risk remains moderate but non‑negligible.
OpenCVE Enrichment