Impact
An out‑of‑bounds read in the Windows Search component allows an authorized local attacker to read memory beyond intended bounds, potentially exposing sensitive data on the host machine. The vulnerability is a classic integer overflow leading to memory disclosure, classified as CWE‑125. The primary impact is limited to local information leakage, with no remote code execution or privilege escalation implied in the description.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, Server 2012 R2, 2016, 2019, 2022, and 2025, including both standard and server core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity impact; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authorized locally to exploit this flaw, meaning typical users or applications with user-level privileges can trigger the information disclosure. Because the exploit requires local access, lateral attack potential is limited, but data leakage could still aid social‑engineering or further attacks if sensitive data is revealed.
OpenCVE Enrichment