Microsoft Windows File Explorer Spoofing Vulnerability
Vulnerability
A spoofing vulnerability has been identified in Windows File Explorer, affecting all supported versions of Microsoft Windows. This vulnerability arises from the exposure of sensitive information to unauthorized actors, allowing them to perform spoofing activities over the network. Successful exploitation requires user interaction, specifically viewing a specially crafted file in the File Explorer Preview Pane.
Impact
Exploitation of this vulnerability could lead to unauthorized spoofing over the network.
Remediation
Users can apply the security update for this vulnerability, which is available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5066791, KB5066835, KB5066836, KB5066872, KB5066873, KB5066874, KB5066876, KB5066877, and KB5066840.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
