Impact
The vulnerability arises from improper handling of Windows hard links within compressed folders. An attacker who can create or access a hard link in a compressed folder can read files that should be inaccessible, exposing sensitive data over a network. This falls under CWE-65, which describes improper handling of hard links.
Affected Systems
Affected are Microsoft Windows 11 releases 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2025 in both Standard and Core installations. Systems running these versions may expose their compressed‑folder contents to unauthorized remote actors.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is 1%, suggesting limited data on current exploitation risk. It does not appear in the CISA KEV catalogue. An attacker would need network access to the target machine and the ability to create or manipulate hard links to compressed folders, which can be achieved through remote file operations. Based on the description, the likely attack vector is a remote network operation that allows direct access to the Windows compressed‑folder file system.
OpenCVE Enrichment