Windows LNK File Vulnerability Exploited by Threat Actors, Researchers Warn

06 Aug 2024

Threat actors have been exploiting a vulnerability in the way Windows processes LNK files, particularly those with unconventional target paths and internal structures. This exploitation allows malicious payloads to bypass built-in security measures, effectively deceiving users into executing harmful files.

Researchers from Elastic Security Labs have uncovered numerous samples on VirusTotal that demonstrate this vulnerability’s active use, with the earliest identified instance dating back over six years. This highlights a persistent issue that has been lurking in the shadows of cybersecurity.

Windows’ In-Built Protections

Attackers are continually devising innovative strategies to circumvent Microsoft’s protective measures, including SmartScreen and Smart App Control (SAC). SmartScreen, a longstanding security feature, is designed to shield Windows users from potentially harmful webpages and files downloaded from the internet or restricted sites. It operates by cross-referencing files against a dynamic list of reported phishing and malicious software sites.

Files that are flagged with Mark of the Web (MotW) metadata are subjected to additional scrutiny. SmartScreen checks these against an allowlist of recognized executables. If a file is not included in this list, SmartScreen intervenes, preventing execution and issuing a warning. Users may choose to override this caution unless enterprise administrators have implemented policies to restrict such actions.

Similarly, Smart App Control enhances security by verifying applications against a database of known safe apps. As explained by the researchers, “SAC works by querying a Microsoft cloud service when applications are executed. If they are known to be safe, they are allowed to execute; however, if they are unknown, they will only be executed if they have a valid code signing signature.” When SAC is enabled, it effectively replaces and disables Defender SmartScreen.

LNK Stomping = Simple MotW Bypass

In a bid to bypass these protective measures, attackers have resorted to signing malware with legitimate code-signing certificates, repurposing reputable applications, or manipulating binaries to appear harmless enough to be included on the known safe app list. The latest technique identified by researchers, termed “LNK stomping,” enables attackers to circumvent Mark-of-the-Web (MOTW) controls by crafting LNK (Windows shortcut) files with non-standard target paths or internal structures.

This manipulation compels Windows to canonicalize or “fix” the path or structure of the file, effectively erasing the MotW metadata. In the absence of this metadata, both SmartScreen and SAC mistakenly classify the file as safe, allowing it to execute without any warning.

Researchers illustrated this vulnerability with simple examples: appending a dot or space to the target executable path (e.g., powershell.exe.) or creating an LNK file with a relative path such as .target.exe. Another variant involves crafting a multi-level path within a single entry of the LNK’s target path array.

Details regarding this bug have been disclosed to the Microsoft Security Response Center, which has indicated that a fix may be forthcoming in a future Windows update. In the interim, researchers advise security teams to meticulously scrutinize downloads within their detection frameworks, emphasizing that reliance solely on OS-native security features is insufficient for robust protection in this domain.

How to connect to a network drive Windows 11?

1. Open File Explorer. 2. Click on 'This PC' in the left pane. 3. Click the 'Computer' tab, then select 'Map network drive'. 4. In the 'Drive' drop-down, select an available drive letter. 5. In the 'Folder' field, enter the path to the network drive (e.g., \\servername\sharename). 6. If necessary, check 'Reconnect at sign-in' to automatically reconnect. 7. Click 'Finish'. 8. If prompted, enter your network credentials.

How to change screen timeout settings on Windows 10?

1. Open Settings by pressing Win + I. 2. Go to 'System' and then select 'Power & sleep'. 3. Under 'Screen', find the 'On battery power, turn off after' and 'When plugged in, turn off after' settings. 4. Use the drop-down menus to select the desired timeout period for each scenario.
Close All Windows

Close All Windows download for free to PC or mobile

Latest update Close All Windows download for free for Windows PC or Android mobile

4
556 reviews
3143 downloads

News and reviews about Close All Windows

10 Jun 2025

Windows 11 Updates Address Security and Enhance Features

Microsoft rolls out mandatory Windows 11 updates, KB5060842 and KB5060999, improving security and introducing new features like cross-device resume in OneDrive, updated search, and an extended System Restore option, adjusting build numbers for versions 24H2 and 23H2.

Read more

06 Jun 2025

Windows 11 Challenges and Evolution in Gaming Handhelds

Exploring Windows 11's journey in gaming handhelds amidst past miscues. Microsoft's evolution with new designs and features unfolds, shaping the mobile space.

Read more

06 Jun 2025

Microsoft Eases Users Toward Windows 11 as Support for 10 Ends

Microsoft nudges users from Windows 10 to Windows 11 as support ends. The company's campaign plays on security risks of outdated systems, sparking mixed responses.

Read more

05 Jun 2025

Microsoft to Allow More Control on Windows in Europe by 2025

The upcoming changes to Windows in Europe, prompted by the Digital Markets Act, will allow users greater control over pre-installed apps and default services, beginning June 2025.

Read more

04 Jun 2025

Strategies for an Optimal Windows 11 Upgrade Experience

Explore essential steps to optimize your Windows 11 upgrade, from tweaking the taskbar to enhancing privacy settings.

Read more

03 Jun 2025

Windows 11 Introduces New Quick Recovery Features

Windows 11's Recovery settings aim for quick machine recovery, offering enhanced options for troubleshooting and system restoration, particularly aiding IT administrators.

Read more

02 Jun 2025

Microsoft Resolves Windows 11 Startup Failures in Virtual PCs

Microsoft releases urgent fixes for Windows 11 startup issues in virtual environments due to missing ACPI.sys file. The updates, now available, underline the challenges in maintaining software security.

Read more

02 Jun 2025

Windows 11 Update Enhances Gaming Features and Performance

Windows 11's latest update fixes game bugs, boosts performance, and adds innovative features like Click to Do and Cross Device Resume.

Read more

02 Jun 2025

Windows Sends Out Emergency Update After System Errors

Microsoft responds to errors in Windows 11 following update KB5058405, issuing a non-security patch KB5062170 to address recovery issues affecting virtual systems.

Read more

02 Jun 2025

Windows Users Face Critical Upgrade Decisions Amid Security Risks

Microsoft urges Windows users to upgrade to Windows 11 as Windows 10 support ends soon, warning of security risks. Asus showcases AI advancements in new PCs.

Read more