Impact
An out‑of‑bounds read in the Windows Image Acquisition component permits an attacker with local, authorized privileges to read memory beyond intended bounds, exposing sensitive data. The vulnerability is classified as CWE‑125, indicating a buffer overread condition that can reveal confidential information. Because the read is performed locally, the disclosure cannot spread over the network, but any information obtained by the user can compromise system confidentiality.
Affected Systems
The flaw affects multiple Windows platforms, including Windows 10 version 1607 through 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and various Windows Server releases such as 2012, 2012 R2, 2016, 2019, 2022 and the upcoming 2025. Microsoft has listed these operating systems as vulnerable in the CVE advisory. Precise version ranges beyond those listed are not enumerated.
Risk and Exploitability
The base score of 4.7 indicates moderate impact in the CVSS v3.1 framework. No EPSS score is currently available, and the issue is not listed in the CISA KEV catalog. Because the exploit requires local, privileged execution, it is unlikely to be leveraged remotely. Nonetheless, any local attacker who can execute code or invoke the acquisition APIs may extract protected data. Remediation is limited to applying the vendor‑issued patch or updating the operating system when available.
OpenCVE Enrichment