Impact
The flaw is a use-after-free bug in the Windows Overlay Filter component that lets an authorized attacker read memory and transmit the contents over a network connection. This leads to an information‑disclosure vulnerability labeled with CWE‑126 (Buffer Over‑Read) and CWE‑416 (Use‑After‑Free). The attacker only needs local privileges on the target system and can cause sensitive data to be sent to an adversary, but the flaw does not provide a path for remote code execution or privilege escalation.
Affected Systems
Affected Microsoft products include Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 variants 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012 R2, 2016, 2019, 2022 and 2025, including both full and Server‑Core installations.
Risk and Exploitability
The CVSS base score is 4.8, indicating moderate impact and limited attack complexity. The EPSS score is currently unavailable, so the probable exploitation frequency is unclear, and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented active exploitation. From the description it appears the attack vector requires local code execution on the target machine with the ability to send data over the network; an attacker could trigger the exploit by invoking the vulnerable Overlay Filter from an authorized application or by leveraging a compromised user account. Because the exploit requires an authorized user, the threat to remote, unauthenticated attackers is low.
OpenCVE Enrichment