logo

Shift Happens – Uncovering Two Built-in Command Injections in Windows Context Menus

ID: b4a0fc49-76f6-59c8-b731-06193c36ae5e

STIX ID: report--b4a0fc49-76f6-59c8-b731-06193c36ae5e

Feed Name: SpecterOps Blog

Threat Score
65/100

Date Published: 2026-05-07

Date Updated: 2026-05-08

...
...

**Executive summary:** This research identifies two command-injection vulnerabilities in Windows Explorer's "Open PowerShell window here" context menu—introduced in Windows 10 1703 and present in many Windows 11 builds—where improperly quoted %V template values allow attacker-controlled folder names to inject and execute arbitrary PowerShell commands when a user opens a shell via Shift+Right-Click; proof-of-concepts, exploitation scenarios, and responsible disclosure to MSRC (VULN-150675) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.