Impact
Use of uninitialized resource in Windows Task Scheduler can expose sensitive information to any user with local authorization. The flaw allows the local attacker to read data that should not be available, violating confidentiality. As identified, the weakness is an improper handling of uninitialized resources (CWE-908).
Affected Systems
Affected Microsoft Windows operating systems include Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 version 23H2, as well as Windows Server 2016, 2019, and 2022, in both full and server core installations. These are the specific builds enumerated by Microsoft for this vulnerability.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalogue. As the attack is local to an authorized user, the risk is primarily confined to a single user context; however, any compromised account could gain additional confidential data if the Task Scheduler is misused. Mitigation requires applying the fix through official Microsoft updates, and there is currently no specific workaround provided by Microsoft.
OpenCVE Enrichment