Executive brief
A security flaw has been identified in the Windows Shell, the graphical interface used to manage files and applications on Microsoft Windows. This vulnerability allows an attacker to bypass built-in security protections, potentially leading to unauthorized access or control over a user's system. This issue is particularly serious as it has been observed being actively exploited in the wild.
Technical details
A protection mechanism failure (CWE-693) exists in the Microsoft Windows Shell component. The vulnerability is triggered over a network vector and requires minimal user interaction (UI:R), allowing an unauthenticated attacker to bypass security features and potentially achieve full system compromise (High Confidentiality, Integrity, and Availability impact). Affected versions include Windows 10, Windows 11, and various Windows Server editions. Microsoft has released security updates to address this flaw, which is currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
Affected products
- Microsoft Windows 10, 11, Server 2012, Server 2016, Server 2019, Server 2022, Server 2025
Timeline
- 2026-02-10: disclosed
- 2026-02-10: advisory: Microsoft released vendor advisory and CISA added to KEV catalog
- 2026-02-10: exploited: Confirmed active exploitation in the wild