CVE-2026-22561
HIGHClaude Desktop - Windows < 1.1.3363 - Local Privilege Escalation via DLL Search-Order Hijacking
Title source: llmDescription
Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking. The installer loads DLLs (e.g., profapi.dll) from its own directory after UAC elevation, enabling arbitrary code execution if a malicious DLL is planted alongside the installer.
References (1)
Core 1
Scores
CVSS v3
7.8
EPSS
0.0018
EPSS Percentile
7.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-427
Status
published
Products (3)
anthropic/claude
< 1.1.3363
Anthropic/Claude Desktop - Windows
< 1.1.3363
Anthropic/Claude Desktop - Windows
1.1.3363
Published
Mar 31, 2026
Tracked Since
Mar 31, 2026