Impact
The vulnerability arises when Windows File Explorer discloses private data to an attacker who has already local authorized access. This flaw is a classic information‑disclosure weakness (CWE‑200) that lets the attacker read sensitive files or configuration data that should be protected, thereby compromising confidentiality on the affected system.
Affected Systems
Affected are Microsoft Windows 10 and Windows 11 clients, including versions 1607, 1809, 21H2, and 22H2 for Windows 10; versions 24H2, 25H2, and 26H1 for Windows 11 on x86, x64, and ARM64 architectures. The flaw also impacts all Windows Server releases from 2016 through 2025, in both full and Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk, while the EPSS score below 1% suggests the vulnerability is unlikely to be actively exploited today. Since the issue requires local authorized access, the attack scope is limited to the compromised workstation or server, and it is not listed in the CISA KEV catalog.
OpenCVE Enrichment