Impact
An out-of-bounds read in the Windows CD‑ROM driver enables an attacker with physical access to read data beyond intended boundaries. The vulnerability can reveal sensitive information stored on or accessed via the CD‑ROM device, thereby compromising confidentiality. It is classified as a CWE‑125 type flaw, which indicates a read past the end of a buffer.
Affected Systems
Microsoft Windows operating systems including Windows 10 version 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both full and Server Core installations).
Risk and Exploitability
The CVSS score of 4.6 places the flaw in the moderate risk range. EPSS data is not available, and the vulnerability is not listed in CISA KEV, which suggests limited public exploitation. However, because the attack requires physical access to the CD‑ROM device, the risk is elevated in environments where such access is feasible. Without an official patch, the likelihood of exploitation remains uncertain but physical security controls are essential.
OpenCVE Enrichment