Microsoft Windows Server
cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*
A vulnerability in the Windows USB Video Class System Driver allows an authorized attacker to locally disclose sensitive information. This issue arises from the generation of error messages that contain confidential data, such as specific memory addresses within kernel space. Knowledge of these memory locations could potentially be exploited for further malicious activities.
Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information, specifically certain memory addresses within kernel space.
Users can download the security update for this vulnerability via the Microsoft Update Catalog. The update is included in the October 2025 Patch Tuesday release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.