Impact
The vulnerability is a Win32K kernel‑user-level interface flaw that causes sensitive system information to be disclosed by an authorized local attacker. It is classified under CWE‑497, which involves information exposure due to resource allocation errors or unintended data leaks. Based on the description, it is inferred that the exposed information may include system configuration data that a local attacker could leverage.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2) and Windows 11 (versions 23H2, 24H2, 25H2, 26H1) along with Windows Server 2012 through 2025, including core installations, are affected. The vulnerability spans both x86 and x64 architectures as well as ARM64.
Risk and Exploitability
The CVSS score of 5.6 indicates a moderate risk profile. The EPSS score of 0.00379 (less than 1%) suggests a very low exploitation probability, and the vulnerability is not listed in CISA KEV, so the likelihood of widespread exploitation remains uncertain. The likely attack vector is a local user with appropriate privileges that can interact with Win32K and trigger the information disclosure. An attacker would need to run code with sufficient rights to invoke the vulnerable function, so mitigation requires addressing the flaw through official updates and limiting local privileged access.
OpenCVE Enrichment