PT-2026-29282 · Anthropic · Claude Desktop - Windows

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-22561

CVSS v4.0

4.7

Medium

AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking. The installer loads DLLs (e.g., profapi.dll) from its own directory after UAC elevation, enabling arbitrary code execution if a malicious DLL is planted alongside the installer.

Fix

Related Identifiers

CVE-2026-22561

Affected Products

Claude Desktop - Windows