CVE-2026-20834
4.6
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.9 / Impact: 3.6
Source: secure@microsoft.com (Secondary)
Description
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
Affected (19)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.14393.8783 | |
| Before 10.0.17763.8276 | |
| Before 10.0.19044.6809 | |
| Before 10.0.19045.6809 | |
| Before 10.0.22631.6491 | |
| Before 10.0.26100.7623 | |
| Before 10.0.26200.7623 | |
| All versions | |
| All versions | |
| Before 10.0.14393.8783 | |
| Before 10.0.17763.8276 | |
| Before 10.0.20348.4648 | |
| Before 10.0.25398.2092 | |
| Before 10.0.26100.32230 |
Related CWEs
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
CWE-36
Absolute Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.
References (1)
Source: secure@microsoft.com
Vendor Advisory
Timeline
No history available yet.