Impact
An integer underflow flaw in the Microsoft Windows SCSI Class System File enables an unauthorized attacker to read sensitive data from a device over a network. The vulnerability is classified as CWE-191, where a wraparound condition in the driver’s request handling can expose internal memory contents. The impact is limited to leakage of information and does not provide control over the system or denial of service.
Affected Systems
Affected operating systems include Microsoft Windows 10 builds 1607, 1809, 21H2, and 22H2; Windows 11 builds 23H2, 24H2, 25H2, 26H1, and 23H2; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025. All listed versions are impacted by the integer underflow in the SCSI Class System File.
Risk and Exploitability
The baseline CVSS score of 6.5 indicates moderate severity. The EPSS score is not provided, and the vulnerability is not listed in CISA KEV, making the exact likelihood of exploitation uncertain. The attack vector is inferred to be remote, as the flaw allows disclosure over a network without requiring local privilege or authentication. Exploitation would involve sending crafted requests to the SCSI driver to trigger the underflow and read data.
OpenCVE Enrichment