
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32225 is a protection mechanism failure (CWE-693) in Windows Shell that allows an unauthorized remote attacker to bypass SmartScreen and Mark of the Web (MotW) security features through specially crafted .lnk shortcut files. Disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2012 through 2025. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Microsoft MSRC, GitHub Advisory).
The root cause is classified as CWE-693 (Protection Mechanism Failure): Windows Shell fails to correctly enforce SmartScreen and Mark of the Web (MotW) protections when processing malicious .lnk shortcut files. MotW is a Windows security mechanism that tags files downloaded from the internet or received via email, triggering security warnings before execution; this vulnerability allows attackers to craft .lnk files that bypass this tagging and the associated SmartScreen checks. The attack vector is network-based with low complexity, requires no privileges, but does require user interaction (e.g., opening a malicious shortcut delivered via email, web download, or removable media). No public proof-of-concept code has been identified at the time of disclosure (Microsoft MSRC, Feedly Intelligence).
Successful exploitation enables arbitrary command execution and malicious DLL loading on the victim's system without triggering standard security warnings, resulting in complete system compromise with high impact to confidentiality, integrity, and availability. Attackers can deliver malware payloads — including ransomware, infostealers, or remote access tools — that bypass a primary defense layer against social engineering attacks, significantly increasing organizational exposure to malware delivery campaigns. The vulnerability affects all supported Windows client and server versions, broadening the potential attack surface across enterprise environments and increasing the risk of lateral movement following initial compromise (Microsoft MSRC, Feedly Intelligence).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly Intelligence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.076–0.094%, placing it in roughly the 26th percentile for exploitation likelihood within 30 days (GitHub Advisory). No specific threat actor attribution has been reported.
.lnk file: Create a Windows shortcut file engineered to bypass MotW tagging and SmartScreen validation, potentially by manipulating shortcut metadata or leveraging shell parsing quirks that prevent the MotW zone identifier from being applied or checked..lnk file to targets via phishing email attachments, malicious web downloads, or removable media — channels where MotW protections are normally triggered..lnk shortcut, which Windows Shell processes without displaying the expected SmartScreen warning due to the protection mechanism failure..lnk files in user download directories, temp folders, or email attachment staging areas; absence of Zone.Identifier alternate data streams (ADS) on files that should have been downloaded from the internet; unexpected DLLs or executables in user-writable directories.explorer.exe or shell-related processes (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) without corresponding user-initiated actions; unexpected network connections from these processes..lnk file; DNS queries for unusual domains from workstations following shortcut execution.Microsoft released patches on April 14, 2026, as part of the April 2026 Patch Tuesday update cycle. Organizations should immediately apply the relevant cumulative updates to reach the following fixed versions: Windows 11 24H2 (10.0.26100.8246), Windows 11 25H2 (10.0.26200.8246), Windows 11 26H1 (10.0.28000.1836), Windows 10 21H2 (10.0.19044.7184), Windows 10 22H2 (10.0.19045.7184), Windows 10 1809 (10.0.17763.8644), Windows Server 2016 (10.0.14393.9060), Windows Server 2019 (10.0.17763.8644), Windows Server 2022 (10.0.20348.5020), Windows Server 2022 23H2 (10.0.25398.2274), and Windows Server 2025 (10.0.26100.32690). Until patches are applied, organizations should educate users about not opening .lnk files from untrusted sources, implement email gateway controls to filter or quarantine shortcut files, and consider blocking .lnk file execution via AppLocker or Windows Defender Application Control policies (Microsoft MSRC).
The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by multiple security outlets. Qualys and Cisco Talos both included CVE-2026-32225 in their Patch Tuesday analysis, highlighting the risk of MotW/SmartScreen bypass vulnerabilities given their historical use in malware delivery campaigns (Qualys Blog, Talos Intelligence). The Hacker Wire published a dedicated article on the vulnerability, noting its potential for enabling malware delivery without security warnings (The Hacker Wire). SOCRadar and CyberInsider also flagged it in their April 2026 zero-day and patch coverage (SOCRadar).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."