CVE-2026-32202
Windows Shell Spoofing Vulnerability
- Published
- Apr 14, 2026
- Updated
- Aug 14, 2026
- Assigning CNA
- microsoft
- Evidence observed
- Apr 28, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NHigh · next 30 days
- Percentile
- 99.2%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
Sources
4- CVE-2026-32202Research
Technical analysis of CVE-2026-32202, a zero-click NTLM credential coercion via crafted .lnk Control Panel applet items in Windows Explorer.
- CVE-2026-32202Exploit
Generates malicious LNK files to coerce Net-NTLMv2 hashes via Windows Shell UNC handling, with custom SMB listener and relay integration for authorized red team operations.
Generates LNK files with crafted _IDCONTROLW structures to research Windows Shell spoofing vulnerabilities CVE-2026-21510 and CVE-2026-32202, including reverse engineering of shell32.dll internals.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.