Impact
An out‑of‑bounds read occurs in the Windows Win32K graphics subsystem, allowing an authorized local attacker to read memory that should be protected. The vulnerability is classified as a buffer read overwrite (CWE‑125) and can lead to disclosure of sensitive information such as passwords or cryptographic keys. The impact is strictly local, and the attack requires the attacker to gain local execution privileges on the affected machine, with no remote exploitation possibility.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, and 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, and 26H1), Microsoft Windows Server 2012 (full and Server Core), Microsoft Windows Server 2012 R2 (full and Server Core), Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows Server 2022, and Microsoft Windows Server 2025.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity assessment. With the attack vector limited to local privilege, the risk is confined to systems accessed by potentially malicious users; the EPSS score is unavailable, but the lack of remote triggers lowers the overall threat level. Microsoft does not list this vulnerability in its KEV catalog, suggesting no known mass exploitation campaigns. Nevertheless, local attackers with elevated privileges can gain valuable information, and the vulnerability should be remediated promptly to prevent potential data leakage.
OpenCVE Enrichment