Executive brief
A security vulnerability in Windows File Explorer could allow a person with existing access to a computer to view sensitive information they are not authorized to see. File Explorer is the standard tool used for managing files and folders on Windows systems. An exploit could lead to the unauthorized disclosure of private data stored on the local machine.
Technical details
An information disclosure vulnerability (CWE-200) exists in Windows File Explorer. The flaw allows an authenticated attacker with local access to the system to bypass intended restrictions and view sensitive data. The attack vector is local, requiring the attacker to have low-privileged access to the target machine. Successful exploitation results in high confidentiality impact but does not affect system integrity or availability. Microsoft has released security updates for various versions of Windows 10 and Windows 11 to address this issue.
Affected products
- Microsoft Windows 10 Version 1607 < 10.0.14393.9339
- Microsoft Windows 10 Version 1809 < 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 < 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 < 10.0.19045.7548
- Microsoft Windows 11 Version 23H2 < 10.0.22631.7376
- Microsoft Windows 11 Version 24H2 < 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 < 10.0.26200.8875
- Microsoft, Windows 11 Version 26H1 < 10.0.28000.2269
Timeline
- 2026-07-14: advisory: Microsoft published the vulnerability details and security updates.
- 2026-07-14: disclosed