VariantDraft
CWE-422Unprotected Windows Messaging Channel ('Shatter')
Category: other
Description
The product does not properly verify the source of a message in the Windows Messaging System while running at elevated privileges, creating an alternate channel through which an attacker can directly send a message to the product.
Common consequences· 1
- Access Control — Gain Privileges or Assume Identity, Bypass Protection Mechanism
Potential mitigations· 1
- [Architecture and Design]Always verify and authenticate the source of the message.
References
(incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-20094cve-2025-20094 | 0% | live |
| Vulnerability | CVE-2025-22894cve-2025-22894 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.