Impact
The vulnerability is an out‑of‑bounds read in the Windows Storage Port Driver. An attacker with physical access can read arbitrary data from memory, potentially exposing private information. The weakness corresponds to CWE‑125 and limits the impact to information disclosure without enabling code execution or privilege escalation.
Affected Systems
Affected systems include several Microsoft Windows releases: Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server from 2012 up through 2025. The flaw is present on both client and server editions and can be exploited on any architecture listed in the CPE data.
Risk and Exploitability
The CVSS score of 4.6 marks this flaw as moderate in severity. EPSS data are not available, and the vulnerability is not listed in the CISA KEV catalog, indicating it is not a widely exploited issue. Because the attack requires physical possession of the device, the likelihood of exploitation is low in highly secured environments, yet it remains a concern in settings with weak physical controls.
OpenCVE Enrichment