CVE-2026-32151 is an information disclosure vulnerability in Windows Shell that allows an authorized attacker with network access to expose sensitive information to unauthorized actors. The vulnerability requires legitimate user credentials to exploit but poses a confidentiality risk without requiring user interaction. This affects the Windows operating system and related shell components. The vulnerability carries a CVSS score of 6.5 (Medium severity) with a network attack vector and low complexity, indicating that exploitation can occur remotely with standard user privileges. While the confidentiality impact is rated as high, there is no integrity or availability impact, meaning attackers cannot modify data or disrupt system functionality. The EPSS score of 0.001 suggests exploitation probability is very low relative to other vulnerabilities in the wild. There is no evidence of active exploitation at this time. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on the Hot List, indicating minimal community attention and no publicly available exploit code. The relatively low FAUCET Risk Score of 35.0 out of 100 further suggests this vulnerability presents a lower priority for immediate remediation compared to other threats in the current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.