Impact
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network, exposing a weakness classified as CWE-693.
Affected Systems
Affected are Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 22H3, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, 2025, and 23H2, including both full and Server Core installations.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, but the EPSS score of 57% shows an increased probability of exploitation. The vulnerability is listed in the CISA KEV catalog, indicating it has been or is expected to be exploited in the wild. Based on the description, the likely attack vector is network-based; an attacker would need to craft spoofed network traffic targeting the vulnerable Windows Shell component.
OpenCVE Enrichment