Impact
This vulnerability allows an authorized attacker to expose sensitive system information from the Windows kernel and transmit the data over a network. The weakness is a kernel-level information disclosure (CWE‑497), which can reveal privileged data that is normally protected by the operating system. The impact is the unauthorized release of confidential information that could be used for further compromise or espionage.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server versions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their server core installations.
Risk and Exploitability
The CVSS score of 5.7 indicates medium severity, and the EPSS score is 0.00995 (<1%), so the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires the attacker to have authorized local access to the system, after which the attacker can transmit the disclosed kernel information over a network. Remote exploitation over the network can occur only if the attacker has already established local privileges; full remote compromise would typically need a separate vulnerability. The EPSS score of 0.00995 (<1%) indicates that exploitation trends are scarce, but some risk remains for local attackers to exfiltrate data.
OpenCVE Enrichment