Executive brief
A security vulnerability has been identified in Windows File Explorer, the standard tool used to browse files and folders on Windows computers. An attacker who already has basic access to a system could exploit this flaw to view sensitive information they are not authorized to see. This could lead to the unauthorized disclosure of private data or internal system details, potentially aiding further attacks.
Technical details
An information disclosure vulnerability (CWE-200) exists in Windows File Explorer due to improper handling of sensitive data. An attacker with local access and low privileges can exploit this flaw to gain access to information that should be restricted. The attack vector is local, meaning the attacker must already have the ability to execute code or log into the target system. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-01-13: disclosed
- 2026-01-13: patched