Microsoft Windows Server 2022
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*
A vulnerability in Windows File Explorer allows an authorized attacker to disclose sensitive information locally. This issue affects several versions of Windows 10, Windows 11, Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2025, and Windows Server 2022. The vulnerability arises from the exposure of sensitive information to an unauthorized actor, potentially leaking the address of a medium integrity process to a lower integrity caller process.
Successful exploitation could lead to unauthorized information disclosure, allowing an attacker to access sensitive data from a local process.
Users can download the security update for their specific Windows version through the Microsoft Update Catalog. Security Update KB5099539 is available for Windows 10 versions 21H2, 22H2, and 1809, as well as for Windows 11 versions 24H2 and 25H2. Windows Server users can refer to KB5099535 for 2016, KB5099538 for 2019, and KB5099536 for 2025. Windows Server 2022 users can also find the relevant security update in the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.