Microsoft Windows 10
cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*
A type confusion vulnerability in Windows Component Object Model (COM) has been identified, allowing an authorized attacker to locally disclose information. This vulnerability arises from the access of resources using incompatible types, which could potentially be exploited to read user mode service memory.
Exploitation of this vulnerability could lead to unauthorized information disclosure.
Users can apply the security update KB5082200 for Windows 10, KB5082052 for Windows 11, KB5082142 for Windows Server 2022, and KB5082063 for Windows Server 2025. For Windows Server 2019, the security update KB5082123 is available. These security updates can be downloaded via the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.