Junglewise Threat Intelligence

CVE-2026-42907: Microsoft Windows Shell information disclosure

CVE-2026-42907 · Severity: medium · CVSS 6.5 · Published 2026-06-09

Technologies: Microsoft Windows Shell. Vendors: Microsoft.

Executive brief

A security vulnerability in the Windows Shell component could allow an authorized user to access sensitive information they are not supposed to see. The Windows Shell is the graphical interface used to navigate the operating system and manage files. While an attacker must already have some level of access to the system, this flaw could lead to the exposure of private data, potentially compromising user privacy or corporate confidentiality.

Technical details

This vulnerability is classified as an Information Exposure (CWE-200) within the Microsoft Windows Shell component. An authenticated attacker with low privileges can exploit this flaw to disclose sensitive information locally. Although the CVSS vector indicates a network attack vector (AV:N), the vulnerability description specifies that the disclosure occurs locally. The root cause is a failure to properly restrict access to sensitive data within the Shell environment. Successful exploitation results in high confidentiality impact but does not affect system integrity or availability.

Affected products

  • Microsoft Windows Shell

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats