VYPR

Windows Shell

by Microsoft

CVEs (42)

  • CVE-2024-43552HigOct 8, 2024
    risk 0.48cvss 7.3epss 0.01

    Windows Shell Remote Code Execution Vulnerability

  • CVE-2025-62565HigDec 9, 2025
    risk 0.47cvss 7.3epss 0.01

    Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-69606HigSep 8, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-69383HigSep 8, 2026
    risk 0.46cvss 7.0epss 0.00

    External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26166HigApr 14, 2026
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26165HigApr 14, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42907MedJun 9, 2026
    risk 0.42cvss 6.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

  • CVE-2026-32151MedApr 14, 2026
    risk 0.42cvss 6.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

  • CVE-2026-20847MedJan 13, 2026
    risk 0.42cvss 6.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

  • CVE-2019-1053MedJun 12, 2019
    risk 0.41cvss 6.3epss 0.01

    An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require…

  • CVE-2026-42906MedJun 9, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

  • CVE-2025-47160MedJun 10, 2025
    risk 0.35cvss 5.4epss 0.01

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-20834MedJan 13, 2026
    risk 0.30cvss 4.6epss 0.01

    Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

  • CVE-2010-3970Dec 22, 2010
    risk 0.08cvss —epss 0.68

    Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allows remote attackers…

  • CVE-2005-0063May 2, 2005
    risk 0.07cvss —epss 0.48

    The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as…

  • CVE-2005-2118Oct 21, 2005
    risk 0.04cvss —epss 0.48

    Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties…

  • CVE-2005-2122Oct 21, 2005
    risk 0.04cvss —epss 0.46

    Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a…

  • CVE-2004-0420Jul 7, 2004
    risk 0.04cvss —epss 0.46

    The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet…

  • CVE-2015-2548Oct 14, 2015
    risk 0.02cvss —epss 0.25

    Use-after-free vulnerability in the Tablet Input Band in Windows Shell in Microsoft Windows Vista SP2 and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Microsoft Tablet Input Band Use After Free Vulnerability."

  • CVE-2015-2515Oct 14, 2015
    risk 0.02cvss —epss 0.29

    Use-after-free vulnerability in Windows Shell in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via…