Executive brief
Windows Compressed Folder has a path traversal vulnerability that allows an authorized local attacker to escape the restricted extraction directory and place files elsewhere on the system. An attacker with local access could exploit this to elevate their privileges by writing malicious files to sensitive system locations during archive extraction.
Technical details
A path traversal flaw in Windows Compressed Folder fails to properly validate extraction paths, allowing an authorized local attacker to use directory traversal sequences (e.g., ../) to write files outside the intended extraction directory. The vulnerability requires local access and authorization but can lead to privilege escalation by placing malicious files in system directories. The issue affects the compressed archive handling component during file extraction operations.
Affected products
- Microsoft Windows Compressed Folder
Timeline
- 2026-09-08: disclosed