CVE-2026-33842
Analyzed Analyzed - Analysis Complete

Information Disclosure in Windows File Explorer

Vulnerability report for CVE-2026-33842, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 24 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_23h2 to 10.0.22631.7376 (exc)
microsoft windows_11_23h2 to 10.0.22631.7376 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-33842 is an information disclosure vulnerability in Windows File Explorer. It allows an authorized attacker with local access to disclose sensitive information to an unauthorized actor. This means that if an attacker has limited privileges on a system, they could exploit this flaw to access data they should not be able to see.

The vulnerability is classified with a CVSS v3.1 BaseScore of 5.5, indicating a medium severity level. The vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N shows that the attack requires local access (AV:L), low attack complexity (AC:L), low privileges (PR:L), no user interaction (UI:N), and has a high impact on confidentiality (C:H) but no impact on integrity or availability.

Detection Guidance

The provided context does not specify methods or commands to detect this vulnerability on a network or system. Detection would typically involve checking for unauthorized access to sensitive information via Windows File Explorer, but no specific tools or commands are mentioned.

Impact Analysis

This vulnerability can impact you in several ways if you are using a system running Windows File Explorer.

  • An attacker with local access to your system could exploit this flaw to access sensitive information stored on your device, such as personal files, credentials, or other confidential data.
  • If the attacker gains access to sensitive information, they could use it for further attacks, such as identity theft, financial fraud, or unauthorized access to other systems.
  • Organizations could face data breaches if this vulnerability is exploited on systems containing regulated or proprietary information.
Compliance Impact

This vulnerability could affect compliance with common standards and regulations in the following ways:

  • GDPR: If the exposed information includes personal data of EU citizens, this could constitute a breach of GDPR. Organizations may be required to report the incident and could face fines if they fail to protect personal data adequately.
  • HIPAA: For healthcare organizations, if the disclosed information includes protected health information (PHI), this could violate HIPAA regulations. Covered entities must ensure the confidentiality of PHI, and a breach could result in penalties.
  • Other regulations: Depending on the industry, other standards like PCI DSS (for payment card data) or SOX (for financial data) could also be impacted if the exposed information falls under their scope.

Organizations should assess whether the vulnerability exposes regulated data and take steps to mitigate the risk to maintain compliance.

Mitigation Strategies

The provided context does not include specific mitigation steps for this vulnerability. However, general best practices for mitigating information disclosure vulnerabilities may apply, such as:

  • Apply the latest security updates from Microsoft as soon as they are available.
  • Restrict local access to sensitive files and directories to authorized users only.
  • Monitor for unusual activity or unauthorized access attempts on systems running Windows File Explorer.
  • Review Microsoft's official guidance for CVE-2026-33842 for any additional mitigation steps or patches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33842. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart