Impact
An out-of-bounds read occurs within Microsoft Windows SCSI Class System File, allowing an adversary who can access the target system physically to read memory locations beyond the intended buffer. This flaw provides unauthorized disclosure of potentially sensitive data stored in the system file, such as credentials, configuration details, or other confidential information. The weakness corresponds to CWE‑125, which denotes out-of-bounds read vulnerabilities that can compromise confidentiality without altering the system state or requiring elevated privileges.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server 2019, Server 2022, Server 2025, including their Server Core installations. All affected editions run on x86, x64, ARM64 architectures as listed.
Risk and Exploitability
The CVSS score of 4.6 places this vulnerability in the medium severity range. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The required attack vector is physical access to the machine with a SCSI Class device, meaning the risk is limited to environments where physical security is inadequate. If such access is possible, an attacker can exploit the out-of-bounds read to disclose confidential information, though the impact does not extend to remote code execution, denial of service, or privilege escalation.
OpenCVE Enrichment