Impact
The vulnerability is an out‑of‑bounds read in the Windows USB driver, allowing an authorized user to read memory beyond protected bounds. The flaw is a buffer over‑read identified as CWE‑125 and can lead to leakage of local information. While it does not provide higher privileges or remote code execution, the exposed data could be sensitive depending on the memory contents.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server 2012 through 2025, including the Server Core installations for 2012, 2012 R2, 2016, and 2019.
Risk and Exploitability
With a CVSS score of 5.5, the flaw is classified as medium severity. The EPSS score of 0.00397 indicates that exploitation is very unlikely, and it is not listed in CISA’s KEV catalog, indicating no widely reported exploitation to date. The likely attack vector is a local authorized user manipulating USB devices or drivers; elevated privileges are not required. Consequently, the risk level is moderate, emphasizing the importance of updating the affected systems to mitigate local information disclosure.
OpenCVE Enrichment