Impact
The vulnerability in Windows File Explorer stems from the use of an uninitialized resource, allowing an unauthorized local attacker to disclose sensitive information. The description does not indicate that remote code execution or privilege escalation is possible; therefore, the impact appears to be limited to local information disclosure. The weakness is classified as CWE-908, indicating improper handling of a private or protected resource.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, and Windows Server 2025 (Server Core installation).
Risk and Exploitability
The CVSS score of 5.5 reflects a medium impact. The EPSS score of less than 1% indicates a very low probability of exploitation. This vulnerability is not listed in CISA KEV. An attacker would need local access to the affected system, making the threat primarily confined to environments where insecure local accounts exist. The overall risk, while moderate, should be mitigated through standard patch management and local account controls.
OpenCVE Enrichment