Impact
The flaw is an out‑of‑bounds read in the Windows Win32K kernel component. When triggered by an authorized local user, the vulnerability allows the attacker to read sensitive memory and ultimately gain elevated local privileges, which can be used to install software or alter system configurations.
Affected Systems
Affected vendors include Microsoft with Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025.
Risk and Exploitability
The CVSS score of 7.8 denotes a moderate‑to‑high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, so the documented likelihood of exploitation is unknown. The attack vector is local and requires the attacker to have authorized user access to trigger the read and elevate privileges.
OpenCVE Enrichment