Impact
This vulnerability allows an authorized local user to access sensitive information through Windows File Explorer. The flaw is a local information disclosure, classified as CWE-200. An attacker who can log into the computer can obtain data that should be protected.
Affected Systems
Affected systems include Microsoft Windows 10 from version 1607 to 22H2, Windows 11 from versions 22H3 through 26H1, and the corresponding Windows Server releases 2016, 2019, 2022, and 2025, including Server Core installations. All of these versions are listed as vulnerable by Microsoft.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity, and the vulnerability is local in scope. No exploitation statistics are available, and it is not listed in the CISA known exploited vulnerabilities catalog. The likely attack path involves interacting with the Windows File Explorer interface, making it accessible only to users with local system access. Therefore, the risk is moderate, but patching is recommended to prevent potential data exposure.
OpenCVE Enrichment