ZeroHour

CVE-2026-70563

mass

Link-Following Spoofing Flaw in Windows Shell (CVE-2026-70563)

CVSS 3.1
8.1 high
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-70563 is an improper link resolution ('link following', CWE-59) vulnerability in the Windows Shell, classified by Microsoft as a spoofing issue. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates it is attackable over a network without privileges or authentication, but exploitation requires user interaction, meaning an attacker must lure a user into interacting with crafted, attacker-controlled content such as a malicious link or shortcut. A successful attack yields what the CVSS scoring rates as high impact to confidentiality and integrity, with no availability impact. Any Windows system containing the affected Windows Shell component is potentially affected, but the available data does not specify affected Windows versions or builds, so defenders should consult Microsoft's (MSRC) advisory for exact scope. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only about a 0.9% probability of exploitation within 30 days (percentile 57).

What to do: Check Microsoft's Security Response Center (MSRC) advisory for CVE-2026-70563 to confirm the affected Windows versions and apply the Windows security update once released. In the interim, caution users against opening links and shortcuts from untrusted sources, since user interaction is required for exploitation. Given no known exploitation or PoC, standard patch-cycle prioritization is reasonable, with escalation if a PoC or in-the-wild exploitation emerges.

Affected
Microsoft Windows (Windows Shell component)
Estimated exposure
mass≈1 billion+ Windows devices (Windows Shell ships with essentially every Windows desktop installation) — Windows is the dominant desktop operating system with an installed base on the order of a billion devices, and the Windows Shell is a core component present on effectively all desktop Windows systems, so nearly all Windows endpoints are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Weakness
CWE-59
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.