CVE-2026-40422
Analyzed Analyzed - Analysis Complete

Use of Uninitialized Resource in Windows File Explorer Allows Local Information Disclosure

Vulnerability report for CVE-2026-40422, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 20 associated CPEs
Vendor Product Version / Range
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-908 The product uses or accesses a resource that has not been initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-40422 is a vulnerability in Windows File Explorer where an uninitialized resource is used. This flaw allows an authorized attacker with local access to disclose sensitive information from the system.

The vulnerability is classified as an information disclosure issue, meaning it does not allow code execution or privilege escalation but can expose confidential data.

  • Affected component: Windows File Explorer.
  • Attack vector: Local (AV:L), meaning the attacker must have access to the system.
  • Privilege requirement: Low (PR:L), indicating the attacker needs some level of authorization.
Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-40422 on a network or system. This vulnerability involves the use of an uninitialized resource in Windows File Explorer, which may not be directly detectable via standard network scanning tools.

To detect potential exploitation or related activity, you may monitor for unusual local information disclosure attempts, such as unexpected file access or memory reads by Windows File Explorer processes. However, no explicit commands or tools are mentioned in the available resources.

Impact Analysis

This vulnerability can impact you by allowing an attacker with local access to your system to disclose sensitive information stored or processed by Windows File Explorer.

  • Potential exposure of confidential files or data handled by File Explorer.
  • Risk of unauthorized access to system information if the attacker exploits the uninitialized resource.

Since the attack requires local access and low privileges, the risk is higher in environments where multiple users share a system or where unauthorized users may gain physical or remote access.

Compliance Impact

This vulnerability may affect compliance with data protection regulations depending on the nature of the disclosed information.

  • GDPR: If the disclosed information includes personal data of EU citizens, it could lead to a breach of GDPR requirements for data confidentiality and security.
  • HIPAA: If the disclosed information includes protected health information (PHI), it could violate HIPAA's safeguards for protecting patient data.

Organizations must assess whether the vulnerability exposes regulated data and take corrective actions to maintain compliance.

Mitigation Strategies

The provided context does not include specific mitigation steps for CVE-2026-40422. However, based on general practices for addressing Windows vulnerabilities, the following actions are typically recommended:

  • Apply the latest security updates from Microsoft as soon as they are available. Check the Microsoft Security Response Center (MSRC) for patches related to this CVE.
  • Restrict local access to systems to only authorized users, as the vulnerability requires local access (AV:L in the CVSS vector).
  • Monitor Microsoft's official communications for additional guidance or workarounds, as they may provide interim mitigations before a patch is released.

For the most accurate and up-to-date mitigation steps, refer to the official Microsoft advisory linked in Resource 1.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40422. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart