Impact
The vulnerability involves exposure of sensitive data within Windows File Explorer, allowing an authorized local user to disclose information that should remain confidential. This weakness is identified as CWE-200 and can compromise the confidentiality of user data without altering system integrity or availability.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 22H3; and Windows Server editions 2016, 2019, 2022, 2025, including both standard and Server Core installations. The vulnerability applies to both x86, x64, and ARM64 architectures across these releases.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate impact. The EPSS score is less than 1%, suggesting a low probability of exploit at present. The issue is not listed in CISA’s KEV catalog. The likely attack vector is a local attacker with legitimate credentials or access to the system, who can invoke the vulnerability through File Explorer. No remote attack surface is described.
OpenCVE Enrichment