Impact
This vulnerability involves improper resolution of path equivalence in the Windows URL Moniker component. The flaw allows an attacker who can send crafted network requests to a system to bypass a security feature that normally restricts access to local resources. As a result, an unauthorized user may gain access to protected resources or execute actions that should be denied. Because the flaw is limited to the URL Moniker resolver mechanics and does not enable arbitrary code execution, the impact is primarily a bypass of a security boundary rather than a full compromise.
Affected Systems
Affected systems include Microsoft Windows 10, starting with version 1607 up to 22H2; Microsoft Windows 11, versions 23H2 through 26H1; and Microsoft Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and server core installations.
Risk and Exploitability
The CVSS score of 4.3 indicates low to moderate severity. The exploit probability is currently unknown, as EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog. The attack is most likely carried out over a network by sending specially crafted URLs to the vulnerable resolver. There is no requirement for local privileges, so remote attackers can trigger the bypass if they can reach the system.
OpenCVE Enrichment