Junglewise Threat Intelligence

CVE-2026-32202: Microsoft Windows Shell protection mechanism failure spoofing

CVE-2026-32202 · Severity: critical · CVSS 4.3 · Exploited in the wild · Published 2026-04-14

Technologies: Microsoft Windows, Microsoft Windows Shell. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows Shell component allows remote attackers to perform spoofing attacks against users. The Windows Shell is the graphical interface used to manage the operating system, including the desktop and file explorer. If exploited, an attacker could trick a user into performing unintended actions or viewing fraudulent information, potentially leading to further compromise of the workstation.

Technical details

A protection mechanism failure (CWE-693) exists in the Microsoft Windows Shell component. The vulnerability is triggered when a user interacts with malicious content over a network, as indicated by the 'User Interaction: Required' metric in the CVSS vector. An unauthenticated attacker can exploit this to perform spoofing, potentially bypassing security warnings or misrepresenting system information. The vulnerability affects a wide range of Windows versions, including Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this issue, and CISA has added it to the Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.

Affected products

  • Microsoft Windows Shell Windows 10, Windows 11, Windows Server 2012, Windows Server 2012 R2

Timeline

  • 2026-04-14: disclosed: Initial disclosure by Microsoft
  • 2026-04-14: advisory: Microsoft MSRC advisory published
  • 2026-04-28: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog

References

Related threats