Reposted by Rémi GASCOU (Podalirius)
Create a folder called (calc). Shift+Right click « Open PowerShell Window here » and boom you have a command injection.
@podalirius.bsky.social found two command injection vulns hiding in Windows Explorer's built-in context menus, both that went undetected for 9 years. ghst.ly/42ImlI6
specterops.io
Shift Happens - Uncovering Two Built-in Command Injections in Windows Context Menus
Two long-standing Windows Explorer vulnerabilities lets attackers execute arbitrary PowerShell commands using crafted folder names, affecting Windows 10 and 11 since 2017.