Microsoft Patches Windows LNK Zero-Day Exploit

04 Dec 2025

Microsoft has released a patch addressing a critical Windows LNK vulnerability that has been actively exploited worldwide. This vulnerability in shortcut files allowed attackers to deliver malware without triggering security warnings, posing a significant threat to users.

Threat Actors' Exploitation

The flaw allowed cybercriminals to embed malicious commands in the shortcut files' Target field, masquerading as harmless content. Upon opening these files, the hidden commands executed with user privileges, allowing malware installation. Major threat groups such as EvilCorp, APT37, and Mustang Panda leveraged this vulnerability to distribute harmful software like Ursnif and Trickbot.

Trend Micro researchers identified the issue in March 2025, but Microsoft delayed the patch, contending that existing warnings sufficed. Threat actors exploited a Mark-of-the-Web loophole to bypass these defenses.

Security Recommendations

Security experts advise against interacting with questionable .lnk files. Enterprises should enforce stringent email and file filtering and disable shortcut execution from untrusted sources. Applying Microsoft's security updates, educating employees on handling unexpected attachments, and using advanced endpoint protection are essential measures.

Monitoring abnormal shortcut file behavior on networks can mitigate potential threats, helping organizations safeguard against similar vulnerabilities.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6756917
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1435957
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
583853
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
464142
downloads

News and reviews for Desktop Windows

Hello Sunshine Revealed at PC Gaming Show, Playtest Opens

Hello Sunshine debuts at the PC Gaming Show. Developed by Red Thread Games, set for 2026 release with playtest sign-ups now open.

Read more

PC Gaming Show: Most Wanted 2025 Highlights Top Games

The PC Gaming Show: Most Wanted 2025 unveils premieres and Council's top 25, featuring GTA 6 and Slay the Spire 2.

Read more

Prime Gaming Offers 14 Free Games in December

Prime Gaming presents 14 free December games, highlighting Deus Ex and retro D&D titles. Games remain after subscription ends.

Read more

PC Gaming Show Reveals 86 Titles for 2025

The PC Gaming Show unveils 86 game titles, including major franchises, set for release in 2025.

Read more

Kill Joy Game Announced for PC: A Unique System-driven Experience

Kill Joy, a unique systems-driven exploration game, announced for PC. Players escape deceptive worlds by making creatures cry.

Read more

Epic Games Store Offers Free Games: Limited Time Access

Epic Games Store presents Free Games this December: The Darkside Detective and Jackbox Party Pack 4 for one week.

Read more

Sony Partners with Bad Robot for New Co-op Shooter

Sony teams up with Bad Robot Games for a co-op shooter on PS5 & PC, led by Mike Booth.

Read more

Microsoft Patches Windows LNK Zero-Day Exploit

Microsoft addressed a critical Windows LNK vulnerability in 2025-10; impact are worldwide malware risks.

Read more

Helldivers 2 Install Size Reduced to 23GB in Beta

Arrowhead optimizes Helldivers 2 on PC, reducing installation size from 154GB to 23GB. New beta shows improved load speeds and space efficiency.

Read more

Prologue Expands with Three DLCs but No Wildlife

Prologue creator Brendan Greene confirms three new DLCs, focusing on game depth but ruling out animal additions.

Read more