PT-2026-24309 · Microsoft · Windows

Christopher Paschen

+1

·

Published

2026-03-10

·

Updated

2026-05-29

·

CVE-2026-25185

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Windows (affected versions prior to March 2026 updates)
Description An issue in Windows Shell Link Processing, specifically within the IShellLink interface, involves the exposure of sensitive information due to insufficient protection of service data. This allows an unauthorized remote attacker to perform spoofing over a network. Technical analysis indicates that specific combinations within ExtraData blocks can be used to silently coerce authentication without requiring any user interaction (zero-click).
Recommendations Apply the March 2026 Windows Updates to resolve the issue.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-03040
CVE-2026-25185

Affected Products

Windows