CWE-422Variant

Unprotected Windows Messaging Channel ('Shatter')

Draft in the CWE catalog · 2 CVEs mapped

2
CVEs mapped
7.7
Median CVSS
What it is

The product does not properly verify the source of a message in the Windows Messaging System while running at elevated privileges, creating an alternate channel through which an attacker can directly send a message to the product.

Recent examples
8.8cvss
CVE-2025-20094

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary code may be executed with SYSTEM privilege.

HIGHno explanation yet
0%
epss
6.5cvss
CVE-2025-22894

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary DLL may be executed with SYSTEM privilege.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-422
Abstraction
Variant
Structure
Simple
Status
Draft
References (1)