Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.14393.0 (custom) before 10.0.14393.8957
affected
10.0.17763.0 (custom) before 10.0.17763.8511
affected
10.0.19044.0 (custom) before 10.0.19044.7058
affected
10.0.19045.0 (custom) before 10.0.19045.7058
affected
10.0.22631.0 (custom) before 10.0.22631.6783
affected
10.0.22631.0 (custom) before 10.0.22631.6783
affected
10.0.26100.0 (custom) before 10.0.26100.8037
affected
10.0.26200.0 (custom) before 10.0.26200.8037
affected
10.0.28000.0 (custom) before 10.0.28000.1719
affected
10.0.28000.0 (custom) before 10.0.28000.1719
affected
6.2.9200.0 (custom) before 6.2.9200.25973
affected
6.2.9200.0 (custom) before 6.2.9200.25973
affected
6.3.9600.0 (custom) before 6.3.9600.23074
affected
6.3.9600.0 (custom) before 6.3.9600.23074
affected
10.0.14393.0 (custom) before 10.0.14393.8957
affected
10.0.14393.0 (custom) before 10.0.14393.8957
affected
10.0.17763.0 (custom) before 10.0.17763.8511
affected
10.0.17763.0 (custom) before 10.0.17763.8511
affected
10.0.20348.0 (custom) before 10.0.20348.4893
affected
10.0.25398.0 (custom) before 10.0.25398.2207
affected
10.0.26100.0 (custom) before 10.0.26100.32522
affected
10.0.26100.0 (custom) before 10.0.26100.32522
affected
Description
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
Problem types
CWE-41: Improper Resolution of Path Equivalence
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23674 (MapUrlToZone Security Feature Bypass Vulnerability)