Junglewise Threat Intelligence

CVE-2026-42906: Microsoft Windows Shell information disclosure

CVE-2026-42906 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Microsoft Windows Shell. Vendors: Microsoft.

Executive brief

A security vulnerability in the Windows Shell component could allow a person with existing access to a computer to view sensitive information they are not authorized to see. The Windows Shell is the graphical interface used to interact with the operating system, including the desktop and file explorer. While an attacker must already have a way to run code on the system, this flaw could lead to the exposure of private data or system secrets.

Technical details

An information disclosure vulnerability exists in the Microsoft Windows Shell component due to improper handling of sensitive data, classified as CWE-200. An attacker with local access and low privileges can exploit this flaw to disclose information to an unauthorized actor. The attack vector is local, requiring the attacker to have prior authenticated access to the target system, but no user interaction is required. Successful exploitation results in high confidentiality impact but does not directly affect system integrity or availability. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Shell

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats