Impact
The vulnerability exposes sensitive information to an unauthorized actor in the Windows Shell, allowing an authorized attacker to disclose information over a network. This flaw is identified as CWE-200 and results in information disclosure without requiring privilege escalation.
Affected Systems
Affected Windows 10 releases (1809, 21H2, and 22H2), Windows 11 releases (23H2, 24H2, 25H2, 26H1), and Windows Server editions (2019, 2022, 2025) including Server Core installations are impacted. The Microsoft Security Response Center lists these platforms in the official update guide for CVE‑2026‑42907.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is a network‑based approach, as the vulnerability allows disclosure of information over a network by an authorized attacker. An attacker would need to have some level of access to the Windows Shell, such as legitimate user credentials or a prior compromise, in order to exploit the flaw. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, while the CVSS base score of 6.5 denotes moderate severity. The vulnerability is not listed in CISA KEV, so no widespread exploitation has been reported.
OpenCVE Enrichment