Impact
The Windows CD‑ROM driver contains an out‑of‑bounds read that can be triggered by an authorized local user. The flaw permits reading memory beyond intended boundaries, which can reveal sensitive data. The weakness is identified as CWE‑125 and results in a local information disclosure vulnerability.
Affected Systems
Affected systems are Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, 22H2, as well as Windows 11 versions 23H2, 24H2, 25H2, and 26H1, and Windows Server 2016 and 2019 (including Server Core installs). All listed builds use the default CD‑ROM driver that contains the vulnerability.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. With no EPSS data, the exploitation likelihood is unknown, but the vulnerability is only usable by local users with sufficient privileges. It is not yet listed in the CISA KEV catalog. The potential impact is limited to information disclosure on the local machine. Immediate action is recommended for systems where exposure is a concern, but no public patch has been released yet.
OpenCVE Enrichment