Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | DLL Search‑Order Hijacking in Anthropic Claude for Windows Installer |
Tue, 07 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | DLL Search-Order Hijacking in Anthropic Claude Windows Installer Enables Local Privilege Escalation | |
| Weaknesses | CWE-779 |
Mon, 06 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anthropic claude
Microsoft Microsoft windows |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:anthropic:claude:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Anthropic claude
Microsoft Microsoft windows |
|
| Metrics |
cvssV3_1
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | DLL Search-Order Hijacking in Anthropic Claude Windows Installer Enables Local Privilege Escalation | |
| First Time appeared |
Anthropic
Anthropic claude Desktop |
|
| Weaknesses | CWE-779 | |
| Vendors & Products |
Anthropic
Anthropic claude Desktop |
Tue, 31 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking. The installer loads DLLs (e.g., profapi.dll) from its own directory after UAC elevation, enabling arbitrary code execution if a malicious DLL is planted alongside the installer. | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-05-10T13:58:31.956Z
Reserved: 2026-01-07T15:39:03.440Z
Link: CVE-2026-22561
Updated: 2026-03-31T16:31:29.129Z
Status : Modified
Published: 2026-03-31T16:16:28.850
Modified: 2026-05-10T14:16:47.860
Link: CVE-2026-22561
No data.
OpenCVE Enrichment
Updated: 2026-04-08T20:00:18Z