PT-2026-29282 · Anthropic · Claude Desktop - Windows+1

CVE-2026-22561

·

Published

2026-03-31

·

Updated

2026-07-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anthropic Claude for Windows versions prior to 1.1.3363
Description The installer (Claude Setup.exe) contains uncontrolled search path elements that allow local privilege escalation through DLL search-order hijacking. This occurs because the installer loads DLLs, such as profapi.dll, from its own directory after User Account Control (UAC) elevation. An attacker can achieve arbitrary code execution by placing a malicious DLL in the same directory as the installer.
Recommendations Update to version 1.1.3363 or later.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22561

Affected Products

Claude Desktop - Windows
Claude