PT-2026-24309 · Microsoft · Windows
Christopher Paschen
+1
·
Published
2026-03-10
·
Updated
2026-05-29
·
CVE-2026-25185
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows (affected versions prior to March 2026 updates)
Description
An issue in Windows Shell Link Processing, specifically within the
IShellLink interface, involves the exposure of sensitive information due to insufficient protection of service data. This allows an unauthorized remote attacker to perform spoofing over a network. Technical analysis indicates that specific combinations within ExtraData blocks can be used to silently coerce authentication without requiring any user interaction (zero-click).Recommendations
Apply the March 2026 Windows Updates to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows