ZeroHour

CVE-2026-69383

mass

Local Privilege Escalation in Microsoft Windows Shell

CVSS 3.1
7.0 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-69383 is a local privilege escalation flaw in the Windows Shell, caused by external control of the file name or path (CWE-73), meaning the shell can be made to operate on an attacker-influenced file path. An authorized attacker who already has a low-privileged foothold on a machine can leverage this path manipulation; the attack requires no user interaction but carries high attack complexity (CVSS 3.1: AV:L/AC:H/PR:L/UI:N). On success, the attacker elevates privileges on the local system with high impact on confidentiality, integrity, and availability. Any Windows installation with the affected Shell component is potentially exposed, though the source data does not specify affected version ranges, so defenders should consult Microsoft's advisory for the exact list. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.

What to do: Monitor Microsoft's advisory for CVE-2026-69383 and deploy the patched builds it lists as soon as they are published (no version ranges or fixed builds were provided in the source data, so do not assume any Windows version is or is not affected). Because exploitation requires an existing local foothold, restrict interactive local logon on high-value systems, enforce least privilege, and keep EDR coverage active to catch post-exploitation activity. Re-check KEV and PoC status before prioritizing patching, since current exploitation signals are minimal.

Affected
Microsoft Windows (Windows Shell)
Estimated exposure
mass≈1 billion+ Windows installations (Shell ships with every client Windows install) — Windows is publicly estimated to run on well over a billion active devices and the Windows Shell component is present on essentially all client installations, so the plausibly affected population is the full Windows installed base rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.

Weakness
CWE-73
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.