Executive brief
A security vulnerability in Windows File Explorer could allow a user already logged into a computer to access information they are not authorized to see. File Explorer is the standard tool used for managing files and folders on Windows systems. While this flaw does not allow for remote attacks or total system takeover, it could lead to the exposure of sensitive data stored on the machine.
Technical details
A vulnerability classified as 'Use of Uninitialized Resource' (CWE-908) exists in Windows File Explorer. An attacker with local access and low privileges can exploit this flaw to disclose sensitive information from the system's memory or file structure. The attack vector is local, requiring the attacker to already have an account or access to the target system, but it does not require user interaction. Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server 2016 to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 Standard and Server Core
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory