Impact
This vulnerability occurs when the Windows Storage Port Driver performs an out-of-bounds read, allowing an attacker who has authorized local access to read memory beyond valid bounds. The resulting information disclosure can expose sensitive data stored in memory, potentially including credentials, configuration information, or other confidential data. Only the out-of-bounds read flaw is present; no control flow hijack or execution capability is provided by this flaw.
Affected Systems
The flaw affects multiple Microsoft Windows releases. Specifically, Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and various Windows Server editions including 2012, 2012 R2, 2016, 2019, 2022, and 2025. All listed builds are susceptible.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity, while an EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting current exploitation is not widespread. Based on the description, the likely attack vector is a local authorized attacker—someone with user or higher privileges on the machine—who can execute code in the context of the Storage Port Driver to trigger the out-of-bounds read. No remote exploitation path is indicated, and the flaw does not grant code execution or privilege escalation.
OpenCVE Enrichment