← back
CVE-2026-21510

Windows Shell Security Feature Bypass Vulnerability

CVSS 8.8 HIGHEPSS 25.8%● KEVCWE-693
In short

A flaw in Windows Shell's protection system allows attackers to bypass security features remotely. This means someone over the network could circumvent built-in Windows security controls without proper authorization.

Technical detail

CWE-693 protection mechanism failure in Windows Shell enables remote bypass of security features through network-accessible vectors. The vulnerability requires network access but no user interaction or elevated privileges as pre-conditions, resulting in security control circumvention with potential for privilege escalation or unauthorized system access.

Summary generated and translated by AI from the official description.
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →