Impact
The Windows Shell information disclosure vulnerability permits an attacker with authorized access on a system to reveal sensitive data over the network, constituting a confidentiality breach (CWE-200).
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 22H3, and 26H1; and Microsoft Windows Server editions 2012, 2012 Server Core, 2012 R2, 2012 R2 Server Core, 2016, 2016 Server Core, 2019, 2019 Server Core, 2022, 23H2 Edition Server Core, 2025, and 2025 Server Core.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity; EPSS data are unavailable and the vulnerability is not listed in the KEV catalog, implying a limited likelihood of widescale exploitation. The attacker must first possess authorized user privileges on the machine but can forward the disclosed information to external systems, thereby exposing the system’s secret data to remote adversaries.
OpenCVE Enrichment