Executive brief
A vulnerability in Windows File Explorer could allow an authorized user on a computer to access sensitive information they are not supposed to see. This issue affects various versions of Windows 10, Windows 11, and Windows Server. While an attacker must already have access to the system to exploit this, it could lead to the exposure of private data or system configuration details.
Technical details
An information disclosure vulnerability (CWE-200) exists in Windows File Explorer due to improper handling of sensitive data access. An attacker with local access and low privileges (PR:L) can exploit this flaw to gain access to information that should be restricted. The attack vector is local (AV:L) and requires no user interaction. Microsoft has released security updates to address this issue across affected versions of Windows 10, 11, and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-01-13: advisory: Initial publication by Microsoft and NVD