Microsoft Alters LNK File Behavior to Tackle Vulnerability

03 Dec 2025

Microsoft has adjusted the handling of LNK files to address a high-severity vulnerability (CVE-2025-9491) in Windows exploited by cybercrime and state-backed groups. This flaw allowed attackers to hide malicious commands inside Windows Shell Link (.lnk) files.

LNK Vulnerability Exploitation

Multiple threat groups, including Evil Corp, APT37, Mustang Panda, and SideWinder, have utilized the LNK vulnerability to disguise harmful commands. Attackers often distributed compromised .lnk files in archives like ZIP due to email security limitations.

According to Trend Micro, these groups used payloads such as Ursnif and PlugX, with Mustang Panda notably targeting European diplomats. Microsoft's November update changes the LNK file Properties view to show the complete Target field characters instead of truncating at 260, addressing the flaw partially.

Security Solutions and Gaps

The company's statement emphasized the requirement for user interaction for attacks to succeed, suggesting the vulnerability does not warrant immediate servicing beyond the update. However, researchers warned that attackers could bypass warnings about untrusted files.

ACROS Security introduced an unofficial fix through its 0Patch platform. This micropatch curtails the Target field to 260 characters and alerts users of excessive length, offering wider protection for Windows versions from Windows 7 to Windows 11 22H2 and related server editions. ACROS claims that their solution could mitigate over 1,000 malicious shortcuts identified by researchers.

Ongoing Risks and User Actions

Despite Microsoft's updates, the vulnerability remains only partially addressed. The changes predominantly benefit cautious users who inspect file properties. Users, especially those within targeted sectors, are encouraged to employ mitigation strategies promptly.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6743084
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1430062
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
577560
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
463515
downloads

News and reviews for Desktop Windows

Destiny 2's Renegades Expansion Boosts Player Count on Steam

Destiny 2's Renegades expansion led to a player spike on Steam. Despite Star Wars themes, numbers remain below past peaks.

Read more

Microsoft Fixes LNK Vulnerability Exploited Since 2017

Microsoft patched the long-standing LNK security flaw in Windows as part of the November 2025 update, impacting user security.

Read more

Highlights from PC Gaming Show: Most Wanted 2025 Countdown

PC Gaming Show: Most Wanted 2025 on December 4 reveals top PC games with new trailers and announcements. Anticipated by gamers and industry experts.

Read more

Microsoft Alters LNK File Behavior to Tackle Vulnerability

Microsoft changes LNK file handling in response to exploited vulnerability CVE-2025-9491, affecting multiple cybercrime groups.

Read more

Norsca Rework Highlights Tides of Torment Expansion

Tides of Torment expansion releases 2023-12-04, with Norsca rework featuring new units and mechanics for Sayl the Faithless.

Read more

Microsoft Ad Promotes Copilot, Sparks Mixed Reactions

Microsoft released a Windows 11 ad featuring Copilot, aiming to showcase advanced voice integration. The ad has sparked mixed reactions, potentially inflating expectations.

Read more

Windows Accessibility Upgrades Enhance User Experience

Windows enhances accessibility with new voice and dictation features, benefiting diverse user needs in 2025.

Read more

Helldivers 2 Trims PC Install Size by 85%

Helldivers 2's PC install size reduced to 23 GB from 154 GB, thanks to deduplication efforts by Arrowhead Game Studios and Nixxes Software.

Read more

PCGamingShow to Reveal Top 25 PC Games by 2025

PC Gamer hosts PCGamingShow: Most Wanted on 2025-12-04, unveiling top PC games. Streaming globally, includes exciting game trailers and announcements.

Read more

Windows Concept Imagines 'Liquid Glass' Redesign

YouTube creator unveils Liquid Glass design, reshaping Windows with modern features that fans want Microsoft to consider.

Read more