VYPR

Windows Shell

by Microsoft

CVEs (36)

  • CVE-2018-8414HigKEVAug 15, 2018
    risk 0.75cvss 8.8epss 0.74

    A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

  • CVE-2010-2568HigKEVJul 22, 2010
    risk 0.73cvss 7.8epss 0.91

    Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon…

  • CVE-2026-21510HigKEVFeb 10, 2026
    risk 0.71cvss 8.8epss 0.26

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2020-1286HigJun 9, 2020
    risk 0.58cvss 8.8epss 0.12

    A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote Code Execution…

  • CVE-2026-32225HigApr 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2022-30222HigJul 12, 2022
    risk 0.55cvss 8.4epss 0.01

    Windows Shell Remote Code Execution Vulnerability

  • CVE-2018-8495HigOct 10, 2018
    risk 0.53cvss 7.5epss 0.51

    A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

  • CVE-2016-0179HigMay 11, 2016
    risk 0.53cvss 7.8epss 0.24

    Windows Shell in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Shell Remote Code Execution Vulnerability."

  • CVE-2026-62770HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-27918HigApr 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2025-64661HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49679HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27729HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Windows Shell allows an unauthorized attacker to execute code locally.

  • CVE-2018-0883HigMar 14, 2018
    risk 0.50cvss 7.5epss 0.15

    Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how file…

  • CVE-2025-64658HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-32202MedKEVApr 14, 2026
    risk 0.48cvss 4.3epss 0.64

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2024-43552HigOct 8, 2024
    risk 0.48cvss 7.3epss 0.01

    Windows Shell Remote Code Execution Vulnerability

  • CVE-2025-62565HigDec 9, 2025
    risk 0.47cvss 7.3epss 0.01

    Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26166HigApr 14, 2026
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26165HigApr 14, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

Page 1 of 2