Impact
The vulnerability permits an authorized attacker to insert sensitive information into a file or directory that the Windows Search Component uses and that is externally accessible, enabling data disclosure over a network. This confidentiality impact is classified by CWE-538.
Affected Systems
Affected versions include Windows 11 23H2, 24H2, 25H2, 26H1 and Windows Server 2022 and 2025 (including Server Core installation). These systems use the Windows Search Component for indexing and searching.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate impact rating. The EPSS score (< 1%) suggests a low probability of exploitation. The CVE does not state whether it is present in the CISA KEV catalog. The vulnerability is defined by insertion of sensitive information into an externally accessible file or directory used by the Windows Search Component, so disclosure of data is possible to any network entity able to read that content. No privilege escalation or denial of service are described. Because the CVE does not provide details on the attacker’s capabilities or an exploit method beyond authorized access to the system, the exact attack path cannot be clarified. The risk for environments following standard hardening practices appears moderate but may be higher for systems with publicly shareable Search Component directories.
OpenCVE Enrichment