CVE-2026-22561 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via D…
Medium CVSS: 4.7

CVE-2026-22561

Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking. The installer loads DLLs (e.g., profapi.dll) from its own directory after UAC elevation, enabling arbitrary code execution if a malicious DLL is planted alongside the installer.
Vendor
Anthropic
Product
Claude
CWE
CWE-427
Yayın Tarihi
2026-03-31 16:16:28
Güncelleme
2026-04-06 16:58:22
Source Identifier
support@hackerone.com
KEV Date Added
-

Kategoriler

Referanslar