Executive brief
A security bypass vulnerability exists in the Windows Shell, the component responsible for the desktop user interface and file management. An attacker could exploit this over a network to bypass built-in security protections, potentially leading to unauthorized access or the execution of malicious actions. Successful exploitation requires a user to interact with a malicious file or link, which could result in a full compromise of the affected system.
Technical details
A protection mechanism failure (CWE-693) exists in the Windows Shell component across multiple versions of Windows and Windows Server. The vulnerability is reachable over the network and is triggered when a user interacts with a malicious resource (UI:R). According to the CVSS vector, the exploit can lead to a total loss of confidentiality, integrity, and availability (C:H/I:H/A:H). Microsoft has released security updates to address this issue; administrators should apply the latest cumulative updates for their respective Windows versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 R2 and Base
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory: Microsoft released the security update guide for this vulnerability.