Impact
The vulnerability allows a local attacker with sufficient privileges to read sensitive system data from the Windows kernel. The exposed information may include configuration details, credential storage locations, and other protected data, thereby compromising confidentiality. This is a kernel information disclosure flaw (CWE-497).
Affected Systems
Microsoft Windows 10 versions 1607 through 22H2, Windows 11 versions 23H2 through 26H1, and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025—including their Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk, while the EPSS score of less than 1% reflects a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local; an attacker with system privileges can trigger disclosure by interacting with kernel interfaces that expose internal state. No remote exploitation path is indicated by the available data.
OpenCVE Enrichment