Impact
The vulnerability allows an authorized local attacker to expose sensitive information through the Windows Shell. This is an information‑exposure flaw (CWE‑200) that can reveal confidential data to users who have local access but are not explicitly authorized to view it. The disclosure does not alter system state, integrity, or availability, but it undermines confidentiality for the affected user group.
Affected Systems
Affected systems include specific Microsoft Windows releases: Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 5.5 classifies the issue as moderate in severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. The exploit appears to require local authority, as the vulnerability is described as affecting an authorized attacker. No remote attack vector is indicated, so the risk is confined to local privilege environments.
OpenCVE Enrichment