Impact
The vulnerability involves inserting sensitive information into a file or directory that is externally accessible by Windows Storage. An authorized local attacker can read that data, exposing confidential information stored on the device. This over‑read of data beyond intended boundaries is a classic buffer over‑read condition, classified as CWE‑126, and permits disclosure of data that should remain confidential.
Affected Systems
The flaw applies to a broad range of Microsoft Windows operating systems, including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server editions from 2012 through 2025. All architectures listed in the CPEs—including x86, x64, and ARM64—are affected, covering both full desktop and server core installations.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity. Since the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation remains uncertain. The attack vector is inferred to be local, meaning an attacker must have direct physical or otherwise authorized access to the hardware or the environment where the file can be read. With no public patch or workaround, the risk remains tied to the exposure of data; monitoring, limiting physical access, and timely application of future updates are essential to mitigate potential impact.
OpenCVE Enrichment