CVE-2026-70563
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: secure@microsoft.com (Secondary)
Description
Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
Affected (24)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.14393.9512 | |
| Before 10.0.17763.9245 | |
| Before 10.0.19044.7725 | |
| Before 10.0.19045.7725 | |
| Before 10.0.22631.7582 | |
| Before 10.0.26100.9445 | |
| Before 10.0.26200.9445 | |
| Before 10.0.28000.2954 | |
| All versions | |
| Before 10.0.14393.9512 | |
| Before 10.0.17763.9245 | |
| Before 10.0.20348.5622 | |
| Before 10.0.26100.33438 |
References (1)
Source: secure@microsoft.com
Vendor AdvisoryPatch
Timeline
No history available yet.