Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-33842

CVE-2026-33842: Windows 10 Information Disclosure Flaw

CVE-2026-33842 is an information disclosure vulnerability in Windows File Explorer on Windows 10 1607 that allows authorized attackers to access sensitive data locally. This article covers technical details, impact, and mitigation.

Published:

CVE-2026-33842 Overview

CVE-2026-33842 is an information disclosure vulnerability in Windows File Explorer. An authorized local attacker can leverage the flaw to expose sensitive information to an unauthorized actor. The issue is classified under [CWE-200] Exposure of Sensitive Information to an Unauthorized Actor.

The vulnerability affects a broad set of Microsoft Windows client and server operating systems, from Windows 10 1607 through Windows 11 26H1, and from Windows Server 2012 through Windows Server 2025. Exploitation requires local access and low privileges, and it does not require user interaction. The attack impacts confidentiality only, with no effect on integrity or availability.

Critical Impact

A locally authenticated attacker can read sensitive information handled by Windows File Explorer that should remain isolated to the owning security context.

Affected Products

  • Microsoft Windows 10 (1607, 1809, 21H2, 22H2) across x86, x64, and ARM64 builds
  • Microsoft Windows 11 (23H2, 24H2, 25H2, 26H1) across x64 and ARM64 builds
  • Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025

Discovery Timeline

  • 2026-07-14 - CVE-2026-33842 published to the National Vulnerability Database
  • 2026-07-16 - Last updated in NVD database

Technical Details for CVE-2026-33842

Vulnerability Analysis

The vulnerability resides in Windows File Explorer (explorer.exe) and its supporting shell components. File Explorer handles metadata, thumbnails, previews, and shell namespace extensions on behalf of the logged-on user. Under specific conditions, File Explorer exposes data belonging to a different security context to a local attacker who is already authenticated to the system.

The flaw is mapped to [CWE-200]. The attacker must have a valid local session and low-level privileges, but no elevation or social engineering is required to trigger the disclosure. The confidentiality impact is rated High because the information exposed can include content that the requesting user is not authorized to read.

Root Cause

The root cause is improper isolation of sensitive data processed by File Explorer between security contexts. Shell components that read file metadata, cached previews, or shell property store data do not consistently enforce access boundaries. As a result, protected information reaches an unauthorized caller during normal shell operations.

Attack Vector

Exploitation requires local execution on the target system by an authenticated user. The attacker interacts with File Explorer or its underlying shell interfaces to request resources that surface data owned by another user or process. No network path, no user interaction from the victim, and no privilege elevation are needed. See the Microsoft Security Update Guide for vendor-published technical details.

Detection Methods for CVE-2026-33842

Indicators of Compromise

  • Unexpected access by non-privileged user sessions to shell caches under %LocalAppData%\Microsoft\Windows\Explorer belonging to other users
  • Anomalous invocation of explorer.exe or dllhost.exe (CoCreateInstance shell surrogates) reading files outside the caller's profile
  • Repeated enumeration of shell property stores, thumbnail caches, or Recent items across user boundaries

Detection Strategies

  • Monitor process and file access telemetry for explorer.exe reading paths outside the invoking user's profile directory
  • Alert on cross-profile access to thumbcache_*.db, iconcache_*.db, and shell property store files
  • Correlate low-privileged interactive sessions with shell namespace enumeration events indicative of reconnaissance

Monitoring Recommendations

  • Enable Windows object access auditing on user profile directories and shell cache locations
  • Ingest endpoint process, file, and handle telemetry into a central analytics platform for cross-user access correlation
  • Track patch state of File Explorer components across all Windows 10, Windows 11, and Windows Server hosts to confirm remediation coverage

How to Mitigate CVE-2026-33842

Immediate Actions Required

  • Apply the Microsoft security update referenced in the Microsoft Security Update Guide to all affected Windows client and server builds
  • Inventory endpoints and servers running affected versions and prioritize multi-user and jump-host systems
  • Restrict interactive logon on sensitive systems to trusted administrative users until patches are deployed

Patch Information

Microsoft has issued guidance and updates through the Microsoft Security Response Center. Refer to the Microsoft Security Update Guide for CVE-2026-33842 for the specific KB articles, cumulative updates, and servicing stack requirements corresponding to each affected Windows edition.

Workarounds

  • Limit local interactive access to shared systems, terminal servers, and Remote Desktop Session Hosts until updates are applied
  • Enforce least privilege for standard users and remove unnecessary local accounts on multi-tenant hosts
  • Clear shell caches (thumbcache_*.db, iconcache_*.db) on shared systems to reduce residual data available to a local attacker

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.