ThreatCluster

New CVEs Address Path Traversal Vulnerabilities in Windows

First seen 18 Feb 2026, 14:22 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Two vulnerabilities affecting Windows path parsing have been reported. CVE-2022-41722, published on February 28, 2023, involves a path traversal issue, while CVE-2023-45283, published on November 9, 2023, concerns insecure parsing of Windows paths with a \??\ prefix. Both vulnerabilities could potentially allow unauthorized access to system files.

Timeline

2023-02-28
CVE-2022-41722 published
2023-11-09
CVE-2023-45283 published
2026-02-18
Information published about both CVEs