Impact
An out‑of‑bounds read flaw in Windows Virtualization‑Based Security (VBS) allows a locally authorized attacker to read arbitrary data in memory that should be protected, potentially leaking confidential files or secrets stored on the affected system.
Affected Systems
The flaw is present in Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 and in Windows Server 2025, including the Server Core variant.
Risk and Exploitability
With a CVSS score of 5.5 the vulnerability is considered medium severity. No EPSS value is available and the issue is not listed in CISA KEV, suggesting a lower likelihood of widespread exploitation. The attack requires local authority—such as a privileged user or malware running with elevated rights—and therefore does not provide remote code execution or denial of service.
OpenCVE Enrichment