This new security vulnerability is rated low-risk and it can only be manipulated by local users (rather than via remote attacks).
Windows XP/Vista/2003 - Local security disclosure vulnerability
http://www.frsirt.com/english/advisories/2007/0701
http://secunia.com/advisories/24245/
QUOTE: A weakness has been identified in Microsoft Windows, which could be exploited by malicious users to disclose sensitive information. This issue is due to an error within the directory-change API that does not properly validate user's permission for child objects when retrieving information regarding objects that they do not have "LIST" permissions for. This could be exploited by local attackers to gather information about protected files (e.g. their names), facilitating further attacks.
CVE ID : CVE-2007-0843
Rated as : Low Risk
Remotely Exploitable : No
Locally Exploitable : Yes