Windows Kernel Information Disclosure Vulnerability
An out-of-bounds read vulnerability in the Windows Kernel allows an unauthorized attacker to disclose sensitive information remotely over a network. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across all architectures (32-bit, x64, ARM64, and Server Core installations). Exploitation requires only network access and no authentication or user interaction. Microsoft has released patches for all affected versions.
- Network access to the affected Windows system
- No authentication required
- No user interaction required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/f231d0a8-80c0-4fc4-8c84-47d9b8ba3747Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.