Executive brief
A vulnerability in Windows File Explorer could allow a person with existing access to a computer to view sensitive information they are not authorized to see. File Explorer is the standard tool used for managing files and folders on Windows systems. This flaw could lead to the unauthorized disclosure of private data stored on the local machine.
Technical details
An information disclosure vulnerability (CWE-200) exists in Windows File Explorer. The flaw allows an authorized local attacker to bypass intended access restrictions and disclose sensitive information from the system. The attack requires local access and low privileges, but no user interaction is necessary. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-01-13: disclosed: Initial publication date
- 2026-01-13: advisory: Microsoft advisory published