Impact
An authenticated Windows user can trigger Windows File Explorer to expose sensitive information that is not meant for disclosure. This flaw is classified as a local information‑disclosure vulnerability (CWE‑200). An attacker within the same system can view data that could lead to a breach of confidentiality.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 22H3 and 26H1; and Windows Server 2016, 2019, 2022, 2025 and 23H2 Edition, including all Server Core installations. The issue affects both 32‑bit and 64‑bit builds where applicable.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity, with no publicly known exploits as EPSS data is unavailable and the vulnerability is not in the CISA KEV catalog. Since the exploit requires legitimate user access, the risk is confined to local privilege users. Prompt application of the vendor patch mitigates the risk.
OpenCVE Enrichment