Junglewise Threat Intelligence

CVE-2026-73019: Microsoft Windows URL Moniker path equivalence bypass

CVE-2026-73019 · Severity: medium · CVSS 4.3 · Published 2026-09-08

Executive brief

Windows URL Moniker is a system component that handles URL parsing and processing. A flaw in how it resolves file path equivalence allows an attacker to circumvent a security feature, potentially enabling unauthorized access or action on a victim's system over a network without direct user interaction.

Technical details

This vulnerability exists in Windows URL Moniker's path equivalence resolution logic, which improperly handles alternative path representations. The flaw allows an attacker to craft specially formed URLs that bypass intended security controls. The vulnerability requires network reachability but does not appear to require authentication or user interaction beyond normal system operation. An attacker can exploit this to bypass security features; the specific impact depends on the security mechanism being bypassed. Patches are expected from Microsoft through their standard security update process.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats