Junglewise Threat Intelligence

CVE-2026-44470: Anthropic Claude Desktop privilege escalation in CoworkVMService

CVE-2026-44470 · Severity: high · CVSS 7.8 · Published 2026-05-13

Technologies: Anthropic Claude Desktop. Vendors: Anthropic.

Executive brief

Claude Desktop is an AI-powered application for Windows that allows users to run multiple coding and chat sessions. A security flaw in the application's background service could allow a person with limited access to a computer to gain full administrative control (SYSTEM privileges). This could lead to unauthorized access to sensitive data, system-wide changes, or the installation of malicious software.

Technical details

The CoworkVMService component in Claude Desktop for Windows, which runs with SYSTEM privileges, fails to validate whether the VM bundle directory is a legitimate directory or an NTFS directory junction before performing file operations. A local, non-privileged attacker can replace the user-writable VM bundle directory with a directory junction pointing to a restricted system location. This causes the service to create or overwrite files in that location with SYSTEM ownership, which can be leveraged to achieve full local privilege escalation. The vulnerability is classified as CWE-59 (Improper Link Resolution) and is resolved in version 1.3834.0.

Affected products

  • Anthropic Claude Desktop versions prior to 1.3834.0

Timeline

  • 2026-05-06: advisory: Vendor advisory published on GitHub
  • 2026-05-13: disclosed: CVE published to NVD

References

Related threats