PT-2026-7396 · Microsoft · Windows Shell+1
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Shell (affected versions not specified)
Description
A protection mechanism failure in the Windows Shell allows an unauthorized remote attacker to bypass security features, specifically the Windows SmartScreen mechanism and Windows Shell warnings. This bypass can lead to remote code execution, enabling the attacker to execute arbitrary code on the system. Exploitation requires user interaction, where the attacker convinces a user to open a specially crafted shortcut file (.LNK) or follow a malicious link, often via phishing. Real-world exploitation of this issue has been reported.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
RCE
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Shell
Windows