Impact
An out‑of‑bounds read condition exists in the Xbox component of Windows, allowing a discovery of data that should remain protected. The flaw can cause the operating system to expose memory contents that are not intended for the calling process, potentially revealing sensitive user or system information. The vulnerability is classified as CWE‑125 and can therefore lead to unintended disclosure of information.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2 and 26H1; Microsoft Windows Server 2016 and 2019, including Server Core installations. The vulnerability is present in the Xbox subsystem of these operating systems.
Risk and Exploitability
With a CVSS score of 4.3 the issue is considered low severity. The EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require physical access to the device to trigger the Xbox read operation. No network‑based attack vector is documented. Given the low CVSS and absence of publicly known exploits, the likelihood of widespread attacks appears limited, but the presence of an information‑disclosure condition warrants patching when possible.
OpenCVE Enrichment