Impact
An out-of-bounds read occurs within the Windows Graphics Device Interface, allowing an attacker through the local environment to read memory regions beyond the intended boundary. This flaw can expose sensitive data that resides adjacent to the vulnerable buffer. The vulnerability is inferred to be exploitable only by locally privileged users, as the GDI interface is a system component accessed by user‑mode code. The flaw is classified as CWE‑125 and is described as an out‑of‑bounds read that permits disclosure of data local to the attacker’s process.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server operating systems ranging from 2012 through 2025 across both full and Server Core editions.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, with no EPSS data available to gauge the exploitation probability, and the flaw is not listed in the CISA KEV catalog, suggesting no widespread exploitation. The attack requires local privileges, so the risk is confined to users who can execute code on the target machine. A successful exploitation would expose memory contents only to the attacker’s local session and does not provide remote code execution.
OpenCVE Enrichment