Impact
The flaw in Windows File Explorer allows a local authorized user to read sensitive data that should remain hidden. By exploiting this issue, an attacker can capture confidential file attributes or metadata. This is an information‑disclosure vulnerability (CWE‑200) with a moderate CVSS score of 5.5.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012 R2, 2016, 2019, 2022, 2025; all editions and core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate risk, while the EPSS score of less than 1% shows very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access; the attacker must log in to the affected system and use File Explorer to trigger the disclosure. Since the attack vector is local and requires legitimate user credentials, the overall risk is lower compared to remote or unauthenticated threats.
OpenCVE Enrichment