Impact
A bug in Windows Error Reporting causes an error message to include sensitive information. When a local user triggers an error, the generated message can reveal confidential data, leading to a violation of confidentiality. The flaw is a classic input mishandling scenario, identified as CWE‑209, and does not affect code execution or denial of service but allows a result to be read by an attacker with local authority.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012 R2, 2016, 2019, 2022, 2025, including any Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA KEV, suggesting no known active exploitation. An attacker must be authorized to the affected system to trigger the error, so the attack vector is local. Exploitation would involve inducing a legitimate error and capturing the resulting message, after which sensitive information can be read. Due to the local nature, the impact is limited to the individual account but can be significant if that account has elevated privileges.
OpenCVE Enrichment