Impact
A flaw in Windows Shell enables an authorized attacker to expose sensitive information by spoofing file paths over a network, resulting in an information disclosure vulnerability (CWE‑200). The vulnerability allows a malicious actor to trick a user or system into viewing confidential data that should remain private.
Affected Systems
Affected are Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 22H3; and a broad range of Windows Server releases from 2008 R2 SP1 to 2025, including full and Server Core installations.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium risk level, and the EPSS score of 1% reflects a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. Based on the description, the likely attack vector is network‑based via Windows Shell interactions, requiring the attacker to already possess authorized access to the target system. Overall, the risk is moderate, yet the impact could be considerable in environments where sensitive data is displayed through the file explorer interface.
OpenCVE Enrichment