Impact
The flaw resides in the Win32K graphics subsystem where an uninitialized resource allows a local user with authorized access to read memory that belongs to other processes. Based on the description, it is inferred that the attacker must already have local authenticated privileges; the vulnerability does not provide a path to execute code or escalated privileges beyond the existing account. Because the uninitialized resource is specific to internal Windows structures, the primary impact is the disclosure of potentially sensitive data, classified under CWE‑908.
Affected Systems
Affected releases include Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, either in full or Server Core installations. These operating systems run on x86, x64 and ARM64 architectures as indicated by the listed CPE entries.
Risk and Exploitability
The severity is moderate, reflected by a CVSS score of 4.7, and the vendor’s advisory lists no public exploit or exploitation data (EPSS score not available). Because the flaw can only be leveraged by a local authenticated user, the risk is confined to environments where privileged accounts exist or where users can run code with administrative rights. While this does not grant remote code execution, the disclosed information could aid subsequent attacks. The vulnerability is not present in the CISA KEV catalog, indicating that it has not been actively exploited in the wild as of the last assessment.
OpenCVE Enrichment