CVE-2026-69383
massLocal Privilege Escalation in Microsoft Windows Shell
CVE-2026-69383 is a local privilege escalation flaw in the Windows Shell, caused by external control of the file name or path (CWE-73), meaning the shell can be made to operate on an attacker-influenced file path. An authorized attacker who already has a low-privileged foothold on a machine can leverage this path manipulation; the attack requires no user interaction but carries high attack complexity (CVSS 3.1: AV:L/AC:H/PR:L/UI:N). On success, the attacker elevates privileges on the local system with high impact on confidentiality, integrity, and availability. Any Windows installation with the affected Shell component is potentially exposed, though the source data does not specify affected version ranges, so defenders should consult Microsoft's advisory for the exact list. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.
What to do: Monitor Microsoft's advisory for CVE-2026-69383 and deploy the patched builds it lists as soon as they are published (no version ranges or fixed builds were provided in the source data, so do not assume any Windows version is or is not affected). Because exploitation requires an existing local foothold, restrict interactive local logon on high-value systems, enforce least privilege, and keep EDR coverage active to catch post-exploitation activity. Re-check KEV and PoC status before prioritizing patching, since current exploitation signals are minimal.
| Microsoft Windows (Windows Shell) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-73
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.