Microsoft Windows Information Disclosure Vulnerability in File Explorer
Vulnerability
A vulnerability in Windows File Explorer allows an authorized attacker to locally disclose sensitive information. This issue affects multiple Windows versions, including Windows 10, Windows 11, Windows Server 2016, Windows Server 2022, and Windows Server 2019. The vulnerability arises from the improper handling of addresses from objects operating at a high integrity level within a sandboxed execution environment, potentially exposing this information to unauthorized actors.
Impact
Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information, specifically addresses from high integrity level objects in a sandboxed environment.
Remediation
Users can apply the security update KB5073724 for Windows 10, KB5074109 for Windows 11, KB5073722 for Windows Server 2016, KB5073457 for Windows Server 2022, and KB5073723 for Windows Server 2019. Security Update KB5073379 is also available for Windows Server 2025. Instructions for downloading these security updates are available through the Microsoft Update Catalog.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
