Microsoft Windows 10
cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*
A protection mechanism failure in Windows Shell allows unauthorized attackers to bypass security features over the network. This vulnerability could enable attackers to circumvent SmartScreen protections that use the Mark of the Web to identify files from the internet. Exploitation involves convincing a user to open a specially crafted shortcut file, which can then execute commands or Control Panel applets without proper security handling, potentially leading to arbitrary command execution or loading malicious DLLs.
Exploitation of this vulnerability could allow for unauthorized bypassing of security features, such as SmartScreen protections, potentially leading to the execution of arbitrary commands or the loading of attacker-controlled DLLs.
Users can download the security update for their specific Windows version through the Microsoft Update Catalog. For detailed guidance, refer to the Microsoft Knowledge Base articles KB5082200, KB5082060, KB5083769, KB5082123, and KB5082142.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.