Impact
This vulnerability is an out‑of‑bounds read in the Windows Mobile Broadband stack that permits an attacker to read protected memory and disclose its contents. The primary consequence is the exposure of sensitive data that should be confined to trusted system processes, directly violating confidentiality. The weakness is defined by CWE-125 and can allow the attacker to harvest arbitrary data from memory associated with the broadband subsystem.
Affected Systems
The affected products include several recent builds of Microsoft Windows: Windows 10 Version 21H2 and 22H2, and Windows 11 Versions 23H2, 24H2, 25H2, 26H1 (both arm64 and x64 where applicable). All listed editions are listed as vulnerable via the provided CPE entries.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity information‑disclosure flaw. With an EPSS score of 1%, indicating low exploitation probability, the lack of a KEV listing suggests no widespread exploit campaigns are known yet, but the condition for compromise is likely a network connection to the vulnerable device. An attacker could trigger the read by sending crafted traffic to the Mobile Broadband component, potentially exposing sensitive data without user interaction. Consequently, operators should treat this as a high‑risk vulnerability that requires timely remediation.
OpenCVE Enrichment