PT-2026-7396 · Microsoft · Windows Shell+1

·

CVE-2026-21510

·

Published

2026-02-10

·

Updated

2026-07-14

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Shell (affected versions not specified)
Description A protection mechanism failure in the Windows Shell allows an unauthorized remote attacker to bypass security features, specifically the Windows SmartScreen mechanism and Windows Shell warnings. This bypass can lead to remote code execution, enabling the attacker to execute arbitrary code on the system. Exploitation requires user interaction, where the attacker convinces a user to open a specially crafted shortcut file (.LNK) or follow a malicious link, often via phishing. Real-world exploitation of this issue has been reported.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01630
CVE-2026-21510

Affected Products

Windows Shell
Windows