Impact
The flaw occurs because Windows Shell resolves links before accessing the target file, which allows an attacker to supply a crafted link that points to an unintended local or network resource. When a victim processes the link, their Windows Shell accesses that resource, enabling spoofing over a network. The weakness is classified as CWE‑59.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 in both full installations and Server Core.
Risk and Exploitability
The CVSS score of 8.1 classifies this vulnerability as high severity. The EPSS score is less than 1 %, indicating that, while exploitation risk is very low at the current time, it still exists. The vulnerability is not listed in CISA’s KEV catalog. The vector described in the CVE is a network‑based spoofing attack that allows an unauthorized attacker to craft and distribute a malicious link that, when processed by Windows Shell, forces the victim to resolve and access a target that the attacker controls. Successful exploitation would result in the victim’s Windows Shell following a spoofed link, potentially exposing sensitive resources or user trust to manipulation.
OpenCVE Enrichment