Impact
This vulnerability exposes sensitive information to an authorized local user through Windows File Explorer. The flaw, identified as a CWE-200 information disclosure error, allows a user with local authorization to view data that should remain hidden. The result is a compromise of confidentiality with no impact on integrity or availability.
Affected Systems
Affected by this issue are Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server 2016, 2019, 2022, and 2025, including both default and Server Core installations. All these systems use Windows File Explorer to display file metadata and are susceptible to local disclosure.
Risk and Exploitability
The CVSS score of 5.5 suggests a moderate severity. The EPSS score is below 1%, indicating a very low probability that this exploit is actively used in the wild. Because the flaw requires a local attacker with legitimate user credentials, the attack vector is local and privilege escalation is not necessary. The vulnerability is not listed in the CISA KEV catalog, further reducing the perceived threat, but any local user with access could misuse the exposed metadata.
OpenCVE Enrichment