Description Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Exploitability: 3.9 | Impact: 3.6 Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: None
Affected Packages29 packages Show 24 more packages
🔴 Vulnerability Details2 CVEList MapUrlToZone Security Feature Bypass Vulnerability ↗ 2026-03-10 ▶ GHSA GHSA-4432-c732-m42m: Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network ↗ 2026-03-10 ▶
📋 Vendor Advisories1 Microsoft MapUrlToZone Security Feature Bypass Vulnerability ↗ 2026-03-10 ▶
🕵️ Threat Intelligence1 Wiz CVE-2026-23674 Impact, Exploitability, and Mitigation Steps | Wiz ↗ ▶