CVE-2026-42907: Windows Shell Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
Other sources
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
— NVD
Windows Shell Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7417Patch KB5094127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5256Patch KB5094128 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7219Patch KB5093998 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8655Patch KB5094126 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32995Patch KB5094125 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7417Patch KB5094127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8880Patch KB5094123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2269Patch KB5095051 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8655Patch KB5094126
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42907?
CVE-2026-42907 has a medium severity rating of 6.5.
How does CVE-2026-42907 impact affected systems?
CVE-2026-42907 allows an authorized attacker to disclose sensitive information locally through Windows Shell.
Which versions of Windows are affected by CVE-2026-42907?
CVE-2026-42907 affects Microsoft Windows 10, 11, and various versions of Windows Server including 2019 and 2025.
How do I fix CVE-2026-42907?
To fix CVE-2026-42907, ensure that your affected Windows operating systems are updated with the latest security patches from Microsoft.
What type of vulnerability is CVE-2026-42907?
CVE-2026-42907 is classified as an Information Disclosure vulnerability.