Microsoft Windows Server 2016
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*
An information disclosure vulnerability has been identified in the Windows Quality of Service (QoS) Packet Scheduler. This vulnerability allows the disclosure of certain memory addresses within kernel space. An attacker could potentially leverage this information for malicious activities. The vulnerability affects multiple Windows products and versions, including Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, as well as various versions of Windows 10 and Windows 11.
Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information, specifically certain memory addresses within kernel space. Knowledge of these addresses could potentially be used by an attacker for further malicious activities.
Users can download the security update for this vulnerability via the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5099535, KB5099538, KB5099540, KB5099444, KB5099445, and KB5099536.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.