Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.