Impact
A failure in the protection mechanism of Windows Shell allows an unauthorized attacker to bypass a security feature over a network. The weakness is a failure to enforce a protection mechanism (CWE‑693). The impact could potentially include loss of confidentiality, integrity, and availability if the feature bypass leads to further compromise.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 22H3, 23H2, 24H2, 25H2, 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, and the 23H2 edition. All listed editions are affected, both 32‑bit and 64‑bit or ARM64 where applicable.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8 and an EPSS score of 26 %. It is listed in the CISA KEV catalog, confirming known exploit activity exists. The likely attack vector is over the network, inferred from the description that the bypass can be performed remotely via a crafted request to the Windows Shell service. The CVE description does not specify whether special privileges are required for exploitation.
OpenCVE Enrichment