Impact
This vulnerability stems from the use of an uninitialized resource within the Windows Spaceport.sys driver. The flaw allows an attacker who already has authorized local access to read data that should otherwise remain protected. The weakness is a case of uninitialized data usage, aligned with CWE‑908, which can expose sensitive information to an unauthorized actor with local privileges.
Affected Systems
Microsoft Windows 10 releases 1607 through 22H2, Windows 11 releases 23H2, 24H2, 25H2, 26H1 and Windows Server editions from 2012 R2 through 2025 are all impacted. The list includes both standard and Server‑Core installations, covering both 32‑bit and 64‑bit architectures as indicated by the affected CPE data.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity for local information disclosure. The EPSS score is currently not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented exploitation at the time of this analysis. An authorized attacker with local privileges can exploit the flaw to read data that was not intended for disclosure; no remote exploit path or privilege escalation mechanism is described in the data provided.
OpenCVE Enrichment