CVE-2026-32202MediumCVSS: 4.3Microsoft Windows Shell-Spoofing-Sicherheitslücke (CVE-2026-32202)
Eine Schwachstelle in der Windows-Shell ermöglicht einem nicht authentisierten Angreifer Spoofing-Angriffe über das Netzwerk. Microsoft hat Sicherheitsupdates für alle betroffenen Windows-Versionen veröffentlicht.
METADATEN
- Entdeckt:
- 14.04.2026
- Patch verfügbar:
- Ja
BETROFFENE SYSTEME
- •Microsoft Windows Server 2016 (10.0.14393.0 < 10.0.14393.9060)
- •Microsoft Windows Server 2016 (Server Core Installation) (10.0.14393.0 < 10.0.14393.9060)
- •Microsoft Windows 10 Version 1607 (10.0.14393.0 < 10.0.14393.9060)
- •Microsoft Windows 10 Version 1809 (10.0.17763.0 < 10.0.17763.8644)
- •Microsoft Windows Server 2019 (10.0.17763.0 < 10.0.17763.8644)
- •Microsoft Windows Server 2019 (Server Core Installation) (10.0.17763.0 < 10.0.17763.8644)
- •Microsoft Windows Server 2022 (10.0.20348.0 < 10.0.20348.5020)
- •Microsoft Windows Server 2022
- •23H2 Edition (Server Core Installation) (10.0.25398.0 < 10.0.25398.2274)
- •Microsoft Windows Server 2025 (10.0.26100.0 < 10.0.26100.32690)
- •Microsoft Windows Server 2025 (Server Core Installation) (10.0.26100.0 < 10.0.26100.32690)
- •Microsoft Windows Server 2012 (6.2.9200.0 < 6.2.9200.26026)
- •Microsoft Windows Server 2012 (Server Core Installation) (6.2.9200.0 < 6.2.9200.26026)
- •Microsoft Windows Server 2012 R2 (6.3.9600.0 < 6.3.9600.23132)
- •Microsoft Windows Server 2012 R2 (Server Core Installation) (6.3.9600.0 < 6.3.9600.23132)
- •Microsoft Windows 10 Version 21H2 (10.0.19044.0 < 10.0.19044.7184)
- •Microsoft Windows 10 Version 22H2 (10.0.19045.0 < 10.0.19045.7184)
- •Microsoft Windows 11 Version 23H2 / 22H3 (10.0.22631.0 < 10.0.22631.6936)
- •Microsoft Windows 11 Version 24H2 (10.0.26100.0 < 10.0.26100.8246)
- •Microsoft Windows 11 Version 24H2 (10.0.26100.0 < 10.0.26100.32690)
- •Microsoft Windows 11 Version 25H2 (10.0.26200.0 < 10.0.26200.8246)
- •Microsoft Windows 11 Version 26H1 (10.0.28000.0 < 10.0.28000.1836)
Zusammenfassung
CVE-2026-32202 beschreibt eine Sicherheitsanfälligkeit in der Windows-Shell, die durch einen fehlerhaften Schutzmechanismus (Protection Mechanism Failure) verursacht wird. Ein entfernter, nicht authentisierter Angreifer kann diese Schwachstelle ausnutzen, um Spoofing-Angriffe durchzuführen. Die Schwachstelle wurde von Microsoft als “Important” eingestuft und wird laut Microsoft bereits aktiv ausgenutzt (Exploitation Detected).
Technische Details
Die Schwachstelle liegt in der Windows-Shell-Komponente und erlaubt einem Angreifer das Spoofing von vertrauenswürdigen Inhalten. Für eine erfolgreiche Ausnutzung ist Benutzerinteraktion erforderlich: Ein Angreifer muss dem Opfer eine manipulierte Datei zusenden, die das Opfer öffnen muss. Der CVSS-Vektor lautet CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C.
- CVSS-Score: 4.3 (Medium)
- Angriffsvektor: Netzwerk
- Angriffskomplexität: Niedrig
- Benötigte Privilegien: Keine
- Benutzerinteraktion: Erforderlich
- Auswirkung: Vertraulichkeit (niedrig), Integrität (keine), Verfügbarkeit (keine)
- Ausnutzbarkeit: Funktionierender Exploit-Code verfügbar, aktiv ausgenutzt
Betroffene Systeme
Folgende Microsoft Windows-Versionen sind betroffen:
- Microsoft Windows Server 2016 (10.0.14393.0 < 10.0.14393.9060)
- Microsoft Windows Server 2016 (Server Core Installation)
- Microsoft Windows 10 Version 1607 (10.0.14393.0 < 10.0.14393.9060)
- Microsoft Windows 10 Version 1809 (10.0.17763.0 < 10.0.17763.8644)
- Microsoft Windows Server 2019 (10.0.17763.0 < 10.0.17763.8644)
- Microsoft Windows Server 2019 (Server Core Installation)
- Microsoft Windows Server 2022 (10.0.20348.0 < 10.0.20348.5020)
- Microsoft Windows Server 2022, 23H2 Edition (Server Core Installation) (10.0.25398.0 < 10.0.25398.2274)
- Microsoft Windows Server 2025 (10.0.26100.0 < 10.0.26100.32690)
- Microsoft Windows Server 2025 (Server Core Installation)
- Microsoft Windows Server 2012 (6.2.9200.0 < 6.2.9200.26026)
- Microsoft Windows Server 2012 (Server Core Installation)
- Microsoft Windows Server 2012 R2 (6.3.9600.0 < 6.3.9600.23132)
- Microsoft Windows Server 2012 R2 (Server Core Installation)
- Microsoft Windows 10 Version 21H2 (10.0.19044.0 < 10.0.19044.7184)
- Microsoft Windows 10 Version 22H2 (10.0.19045.0 < 10.0.19045.7184)
- Microsoft Windows 11 Version 23H2 / 22H3 (10.0.22631.0 < 10.0.22631.6936)
- Microsoft Windows 11 Version 24H2 (10.0.26100.0 < 10.0.26100.8246)
- Microsoft Windows 11 Version 24H2 (10.0.26100.0 < 10.0.26100.32690)
- Microsoft Windows 11 Version 25H2 (10.0.26200.0 < 10.0.26200.8246)
- Microsoft Windows 11 Version 26H1 (10.0.28000.0 < 10.0.28000.1836)
Empfehlungen und Maßnahmen
- Sofortige Installation der Sicherheitsupdates: Microsoft hat am 14. April 2026 offizielle Sicherheitsupdates veröffentlicht. Diese sollten umgehend über Windows Update, WSUS oder Microsoft Update Catalog installiert werden.
- Priorisierung: Aufgrund der aktiven Ausnutzung in freier Wildbahn wird eine zeitnahe Installation als kritisch eingestuft.
- Sensibilisierung der Benutzer: Da Benutzerinteraktion erforderlich ist, sollten Mitarbeiter für das Öffnen unverlangt erhaltener Dateien sensibilisiert werden.
- Netzwerksegmentierung: Reduzieren Sie die Angriffsfläche durch Netzwerksegmentierung und Firewall-Regeln.
Quellen
- Microsoft Security Update Guide: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202
- CVE Record (MITRE): https://www.cve.org/CVERecord?id=CVE-2026-32202
- Akamai Research: https://www.akamai.com/blog/security-research