Impact
The vulnerability is a use of an uninitialized resource in the Windows Win32 Kernel Subsystem. This flaw permits an authorized local user to read portions of memory that the system has not yet sanitized, potentially revealing sensitive data. The weakness is classified as CWE‑908 and results in a local information‑disclosure vulnerability affecting confidentiality.
Affected Systems
Affected are multiple Microsoft Windows releases. Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core installations. All listed product variants and architectures (x86, x64, ARM64) are impacted.
Risk and Exploitability
The CVSS score is 5.5, indicating a moderate severity for local threats. No EPSS information is available and the vulnerability is not included in the current CISA KEV catalog. The attack requires local, privileged access; there is no known remote exploitation vector. An offender would need legitimate user credentials or local administrative rights, after which they could trigger the kernel routine and obtain sensitive memory contents. Because the flaw is local, the overall risk is confined to compromised endpoints, but it could still expose authentication tokens, credentials, or other confidential data.
OpenCVE Enrichment