Impact
The vulnerability is an out‑of‑bounds read in the Windows Storage Spaces Controller which permits an authorized user to read memory beyond intended bounds. This results in the disclosure of potentially sensitive data that resides locally on the infected system. The weakness is classified as CWE‑125, which is an out‑of‑bounds read.
Affected Systems
Affected systems include multiple Microsoft Windows client editions such as Windows 10 versions 1607, 1809, 21H2, 22H2, and Windows 11 releases 23H2, 24H2, 25H2, 26H1, as well as Windows Server releases 2012, 2012 R2, 2016, 2019, 2022 and 2025. All mentioned editions, whether server core or full installation, are impacted.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity. EPSS information is not available, so the exact likelihood of exploitation is unknown, and the vulnerability is not listed in CISA's KEV catalog. The attack requires local privilege; the attacker must have authorized access to the system and a sufficiently privileged account to interact with Storage Spaces. Under those conditions, the attacker can read protected memory and gain access to local data, but no elevation of privilege or remote attack path is described.
OpenCVE Enrichment