Impact
The vulnerability allows a local attacker who has legitimate access to disclose sensitive information through Windows File Explorer. Classified as a classic information‑disclosure flaw (CWE‑200), the issue permits revealing data that an unauthorized actor could use for further exploitation.
Affected Systems
The flaw affects multiple Microsoft Windows releases: Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. Because the exploit is local, an attacker must already have authorized access; it is not listed in CISA KEV. Consequently the risk is moderate but could be amplified if privileged users are compromised.
OpenCVE Enrichment