Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Microsoft confirms active exploitation of Windows Shell CVE-2026-32202
Celebrities

Microsoft confirms active exploitation of Windows Shell CVE-2026-32202

By April 28, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 28, 2026Vulnerability/Threat Intelligence

Microsoft on Monday revised its advisory for a currently patched high-severity security flaw affecting Windows Shell, acknowledging that the vulnerability is indeed being actively exploited.

The vulnerability in question is CVE-2026-32202 (CVSS score: 4.3), a spoofing vulnerability that could allow attackers to access sensitive information. This issue was addressed as part of this month’s Patch Tuesday update.

“Failures in the Windows Shell protection mechanisms could allow an unauthorized attacker to perform spoofing on your network,” Microsoft said in a warning. “The attacker sends a malicious file to the victim, and the victim must execute it.”

“An attacker who successfully exploits this vulnerability may view some sensitive information (sensitivity), but not all resources within the affected component will be exposed to the attacker. An attacker will not be able to modify the exposed information (integrity) or restrict access to the resources (availability).”

On April 27, 2026, Microsoft announced that the “Exploitability Index, Exploited Flags, and CVSS Vectors” were incorrect when published on April 14 and have been corrected.

The tech giant did not reveal details of the exploit activity, but Akamai security researcher Maor Dahan, who is credited with discovering and reporting the bug, said the zero-click vulnerability was due to an incomplete patch for CVE-2026-21510.

The latter was weaponized by a Russian nation-state group tracked as APT28 (also known as Fancy Bear, Forest Blizzard, GruesomeLarch, and Pawn Storm) along with CVE-2026-21513 as part of an exploit chain.

CVE-2026-21510 (CVSS Score: 8.8) – Failure in the Windows Shell protection mechanism allows an unprivileged attacker to bypass security features via the network. (Fixed by Microsoft in February 2026) CVE-2026-21513 (CVSS Score: 8.8) – Failure in a protection mechanism in the MSHTML framework allows an unprivileged attacker to bypass security features via the network. (Fixed by Microsoft in February 2026)

It is also worth noting that the CVE-2026-21513 exploit was reported by a web infrastructure and security company early last month after discovering a malicious artifact in January 2026 and was associated with APT28.

CVE-2026-21510 Exploit

Targeting Ukraine and EU countries in December 2025, the campaign leverages malicious Windows Shortcuts (LNK) files to exploit two vulnerabilities that effectively bypass Microsoft Defender SmartScreen and enable the execution of attacker-controlled code.

“APT28 leverages the Windows shell’s namespace parsing mechanism to load dynamic link libraries (DLLs) from remote servers using UNC paths,” Dahan explained. “The DLL is loaded as part of the Control Panel (CPL) object without proper validation of the network zone.

According to Akamai, the February 2026 patch mitigates the risk of remote code execution by digitally signing CPL files and triggering a SmartScreen check on the zone of origin, but still allowed the victim machine to automatically retrieve CPL files by authenticating to the attacker’s server, resolving a Universal Naming Convention (UNC) path, and initiating an SMB connection without requiring user interaction.

“If that path is a UNC path (such as ‘\\attacker.com\share\payload.cpl’), Windows will initiate an SMB connection to the attacker’s server,” Dahan said. “This Server Message Block (SMB) connection triggers an automatic NTLM authentication handshake and sends the victim’s Net-NTLMv2 hash to the attacker, which can later be used for NTLM relay attacks or offline cracking.”

“While Microsoft fixed the initial RCE (CVE-2026-21510), the authentication enforcement flaw (CVE-2026-32202) remained. The gap between path resolution and authenticity verification left a zero-click credential theft vector via automatically parsed LNK files.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleA video game that lets you step into history
Next Article Microsoft patches Entra ID role flaw that allowed service principal takeover

Related Posts

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Nina Dobrev takes on bridal trends beyond white satin in Taorna

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Cardi B, Fat Joe and other musicians react

Trending Posts

BTS’s “Come Over” was chosen as this week’s best new song

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Cardi B, Fat Joe and other musicians react

June 14, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.