CVE-2026-69445
massPath Traversal Privilege Escalation in Microsoft Windows Compressed Folder
CVE-2026-69445 is a path traversal flaw (CWE-22, improper limitation of a pathname to a restricted directory) in the Windows Compressed Folder feature, the built-in ZIP archive handler in Microsoft Windows. Because the feature fails to properly constrain extraction paths, an authorized attacker with low privileges on the local system could craft a compressed folder whose paths escape the intended restricted directory, resulting in elevation of privilege. A successful attack would give the low-privileged user higher-privileged access on that host, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 7.8). Any Windows installation that includes the Compressed Folder feature is potentially affected, though the available data does not list specific affected Windows versions or builds, so defenders should consult Microsoft's advisory for exact ranges. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a roughly 0.4% probability of exploitation within 30 days (29th percentile).
What to do: Install the Windows security update that addresses CVE-2026-69445 once identified in Microsoft's advisory (specific KB/build numbers were not included in the available data). Because exploitation requires an authorized local user, prioritize patching shared, multi-user, and remote-desktop systems where standard users can execute code. No public PoC, in-the-wild exploitation, or documented workaround is known at this time.
| Microsoft Windows Compressed Folder (built-in compressed folder/ZIP handling in Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows Compressed Folder allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.