Impact
This vulnerability is an out‑of‑bounds read in the Windows USB Mass Storage Class driver that can be triggered by an authorized local attacker. The flaw allows the attacker to read data beyond the intended buffer boundaries, potentially exposing memory contents of the system. The impact is limited to the local system and does not provide remote code execution or privilege escalation. The weakness is classified as CWE‑125.
Affected Systems
Affected systems include Microsoft Windows 10 from version 1607 through 22H2, Windows 11 from versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 across both standard and Server Core installations.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The attack vector requires an authorized attacker with local access to a USB mass‑storage interface; the flaw specifically enables information disclosure through an out‑of‑bounds read. Without patching, a malicious user could learn memory contents that may aid further attacks, but no immediate remote threat is implied.
OpenCVE Enrichment