PT-2026-29282 · Anthropic · Claude Desktop - Windows+1
CVE-2026-22561
·
Published
2026-03-31
·
Updated
2026-07-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Anthropic Claude for Windows versions prior to 1.1.3363
Description
The installer (Claude Setup.exe) contains uncontrolled search path elements that allow local privilege escalation through DLL search-order hijacking. This occurs because the installer loads DLLs, such as
profapi.dll, from its own directory after User Account Control (UAC) elevation. An attacker can achieve arbitrary code execution by placing a malicious DLL in the same directory as the installer.Recommendations
Update to version 1.1.3363 or later.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Claude Desktop - Windows
Claude