Impact
This vulnerability is an out‑of‑bounds read that can reveal sensitive data on the local machine. The flaw resides in the Windows Wireless Wide Area Network Service and allows an attacker who has authenticated access to the system to read memory beyond intended boundaries. The disclosure can expose configuration data, credentials, or other confidential information, compromising data confidentiality for a single device or enterprise network if the service is used across multiple hosts.
Affected Systems
The affected products are Microsoft Windows 10 (Version 1607, 1809, 21H2, 22H2), Windows 11 (Versions 23H2, 24H2, 25H2, 26H1), and Windows Server 2016 and 2019 (including Server Core installations). Users of these operating systems need to confirm whether the associated Wireless Wide Area Network Service is installed and active.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring the attacker to have authorized access to the computer. The threat impacts confidentiality by permitting the disclosure of data that should be protected by system memory boundaries, but it does not lead to remote code execution or denial of service with the current information.
OpenCVE Enrichment