Executive brief
A security vulnerability in the Windows Shell component could allow a person with existing access to a computer to view sensitive information they are not authorized to see. The Windows Shell is the graphical interface used to interact with the operating system, including the desktop and file explorer. While an attacker must already have a way to run code on the system, this flaw could lead to the exposure of private data or system secrets.
Technical details
An information disclosure vulnerability exists in the Microsoft Windows Shell component due to improper handling of sensitive data, classified as CWE-200. An attacker with local access and low privileges can exploit this flaw to disclose information to an unauthorized actor. The attack vector is local, requiring the attacker to have prior authenticated access to the target system, but no user interaction is required. Successful exploitation results in high confidentiality impact but does not directly affect system integrity or availability. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Shell
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory