Impact
The issue is an out‑of‑bounds read in the Win32K graphics kernel, which lets a local user read sensitive memory and gain access to private data. The read can expose confidential values that could facilitate further attacks. It is a local information‑disclosure flaw categorized as CWE‑125 and CWE‑193.
Affected Systems
It impacts a wide range of Windows operating systems—including Windows 10 releases from version 1607 through 22H2, Windows 11 releases from 23H2 to 26H1, and Windows Server editions from 2012 up to 2025 in all configurations.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate risk. Because the flaw requires local authorized privileges and no known remote exploitation exists, the danger is limited to users with legitimate access. The vulnerability is not listed in the CISA KEV catalog and EPSS data is not available, indicating limited current exploitation. Nevertheless, prompt patching should be pursued.
OpenCVE Enrichment