ZeroHour

CVE-2026-69445

mass

Path Traversal Privilege Escalation in Microsoft Windows Compressed Folder

CVSS 3.1
7.8 high
EPSS
<1%p29
Published
()
Modified
AI analysis

CVE-2026-69445 is a path traversal flaw (CWE-22, improper limitation of a pathname to a restricted directory) in the Windows Compressed Folder feature, the built-in ZIP archive handler in Microsoft Windows. Because the feature fails to properly constrain extraction paths, an authorized attacker with low privileges on the local system could craft a compressed folder whose paths escape the intended restricted directory, resulting in elevation of privilege. A successful attack would give the low-privileged user higher-privileged access on that host, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 7.8). Any Windows installation that includes the Compressed Folder feature is potentially affected, though the available data does not list specific affected Windows versions or builds, so defenders should consult Microsoft's advisory for exact ranges. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a roughly 0.4% probability of exploitation within 30 days (29th percentile).

What to do: Install the Windows security update that addresses CVE-2026-69445 once identified in Microsoft's advisory (specific KB/build numbers were not included in the available data). Because exploitation requires an authorized local user, prioritize patching shared, multi-user, and remote-desktop systems where standard users can execute code. No public PoC, in-the-wild exploitation, or documented workaround is known at this time.

Affected
Microsoft Windows Compressed Folder (built-in compressed folder/ZIP handling in Windows)
Estimated exposure
mass≈1 billion+ Windows devices (feature is built into Windows) — The Compressed Folder feature ships with Windows itself, so potential exposure tracks the overall Windows installed base (roughly 1.4 billion devices per Microsoft's public statements), although exploitation requires an attacker to already…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows Compressed Folder allows an authorized attacker to elevate privileges locally.

Weakness
CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.