BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Microsoft Quietly Patches Long-Exploited Windows Shortcut Vulnerability

Microsoft patches long-exploited Windows Shortcut (LNK) vulnerability enabling hidden remote code execution

  • Microsoft quietly fixed a security vulnerability exploited since 2017 in November 2025 updates.
  • The issue, CVE-2025-9491, involves a Windows Shortcut (LNK) file flaw enabling remote code execution.
  • The vulnerability hides malicious commands in LNK files by truncating long strings in the properties view.
  • Several state-sponsored groups used this flaw for espionage and Malware delivery campaigns.
  • Microsoft now displays the full command in LNK file properties to prevent this exploit.

Microsoft addressed a long-exploited security vulnerability as part of its November 2025 Patch Tuesday updates. The flaw, identified as CVE-2025-9491, affected Windows Shortcut (LNK) files and has been exploited by threat actors since 2017.

- Advertisement -

This vulnerability allowed attackers to craft .LNK files that misled users by hiding malicious commands in the file’s properties interface. According to the NIST National Vulnerability Database (NVD), a carefully designed LNK file could execute code with the current user’s privileges while appearing benign due to concealed harmful content.

The flaw revolves around the LNK file’s Target field, which supports very long strings of up to 32,000 characters, but Windows’ properties dialog only displayed the first 260 characters. This limitation allowed malicious instructions beyond that length to remain invisible to users inspecting the file, often disguised as harmless documents.

Reports dating back to March 2025 revealed that 11 state-sponsored groups from China, Iran, North Korea, and Russia leveraged this vulnerability for data theft, espionage, and financial gain. Despite early warnings, Microsoft initially chose not to patch it immediately, citing existing user warnings on opening LNK files from unknown sources and user interaction requirements.

Following further abuse by a cyber espionage group named XDSpy and later campaigns delivering malware like PlugX targeting European diplomatic entities, the company issued official guidance on the vulnerability but maintained its position. However, the November 2025 update silently fixed the issue by changing the properties dialog to show the entire Target command line, regardless of length, thus preventing the attack vector.

- Advertisement -

A micropatch developed by ACROS Security’s 0patch offered an alternate solution by warning users when opening files exceeding 260 characters in the Target field. The patch and the official update aim to mitigate this longstanding risk by improving visibility of hidden commands in LNK files.

Microsoft’s security advisory and the technical details of the fix can be found on their security update guide. Further discussion on the vulnerability and its exploitation history was published by ACROS Security’s 0patch blog.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Android 17 Blocks Malware via Accessibility Service Lockdown

Google restricts Android’s accessibility services to verified apps when Advanced Protection is enabled, closing...

SpaceX Millionaire Gains: Decades-Long Project, Not Tesla Jackpot

SpaceX stock (SPCX) trades at $148.07, with Wall Street's average 12-month price target at...

RealFi launches Cardano mainnet after 3,000-wallet testnet

The public testnet drew more than 3,000 verified active wallets, exceeding the company's 2,000...

Teen arrested in Spain as suspected KillSec ransomware admin

Spanish police arrested a 16-year-old Romanian national in Alicante, suspected of being the administrator...

Maximor rebrands as Hyphenate after 86x revenue growth

Hyphenate spans order-to-cash, treasury, general ledger (GL) accounting and close, procure-to-pay, and reporting and...

Must Read

Top 8 Books Every Beginner Should Read About Cryptocurrency

Cryptocurrency and blockchain technology are filled with technical terms that beginners find challenging to understand. One of the best ways to learn about cryptocurrency...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading