CVE-2026-33842: Windows File Explorer Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Other sources
Windows File Explorer Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23291Patch KB5099444 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9339Patch KB5099535 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7548Patch KB5099539 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2525Patch KB5101649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33158Patch KB5099536 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7376Patch KB5099414 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7548Patch KB5099539 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5386Patch KB5099540 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9020Patch KB5099538
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33842?
CVE-2026-33842 has a medium severity rating of 5.5.
What does CVE-2026-33842 affect?
CVE-2026-33842 affects various versions of Microsoft Windows including Windows 10, Windows 11, and Windows Server editions.
How do I fix CVE-2026-33842?
To fix CVE-2026-33842, apply the available security patch from Microsoft.
What type of vulnerability is CVE-2026-33842?
CVE-2026-33842 is classified as an Information Disclosure vulnerability.
Who is at risk from CVE-2026-33842?
CVE-2026-33842 poses a risk to authorized users who may expose sensitive information to unauthorized actors.