Microsoft Patches Windows LNK Zero-Day Exploit

04 Dec 2025

Microsoft has released a patch addressing a critical Windows LNK vulnerability that has been actively exploited worldwide. This vulnerability in shortcut files allowed attackers to deliver malware without triggering security warnings, posing a significant threat to users.

Threat Actors' Exploitation

The flaw allowed cybercriminals to embed malicious commands in the shortcut files' Target field, masquerading as harmless content. Upon opening these files, the hidden commands executed with user privileges, allowing malware installation. Major threat groups such as EvilCorp, APT37, and Mustang Panda leveraged this vulnerability to distribute harmful software like Ursnif and Trickbot.

Trend Micro researchers identified the issue in March 2025, but Microsoft delayed the patch, contending that existing warnings sufficed. Threat actors exploited a Mark-of-the-Web loophole to bypass these defenses.

Security Recommendations

Security experts advise against interacting with questionable .lnk files. Enterprises should enforce stringent email and file filtering and disable shortcut execution from untrusted sources. Applying Microsoft's security updates, educating employees on handling unexpected attachments, and using advanced endpoint protection are essential measures.

Monitoring abnormal shortcut file behavior on networks can mitigate potential threats, helping organizations safeguard against similar vulnerabilities.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7343551
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1696334
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
728191
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
491134
downloads

News and reviews for Desktop Windows

Launches Quarantine Zone with Unique Medical Systems

Quarantine Zone: The Last Check debuts on 2026-01-12. Players act as zombie plague doctors in a repetitive yet engaging simulation.

Read more

Disney Delists 14 Games from Steam, Impacting Preservation

Disney removed 14 PC games from Steam without notice, affecting game preservation enthusiasts.

Read more

Windows 10 Update KB5073724 Enhances Security for Business Users

Microsoft's KB5073724 improves security for Windows 10 ESU users. Key changes include Secure Boot updates and legacy driver removal.

Read more

Hytale Plans Future Controller Support: Current Workarounds

Hypixel Studios plans future controller support for Hytale, aiding Steam Deck play. Current workarounds exist.

Read more

Initial Drift Free on Steam for 48 Hours

RewindApp's Initial Drift Online is free on Steam until January 18. Discover the impacts of this offer on reviews and gameplay.

Read more

Fanatical Introduces Build Your Own Indie Bundle for 2026

Fanatical's Indie Legends BYOB offer lets you create a custom Steam game bundle. Tiered pricing available until 2026-02-19.

Read more

0patch Extends Windows 10 Security Beyond Microsoft Support

0patch provides micropatches for Windows 10 after Microsoft support ended in 2025, offering a security alternative.

Read more

Lovish Set to Launch on Steam with 50+ Levels

LABS Works to release Lovish, a puzzle platformer, on Steam on February 5, featuring 50+ levels and Astalon-style elements.

Read more

Epic Games Store Offers Free Styx Stealth Games

Epic Games Store offers Styx games free until 2023-01-22. Prepare for Styx: Blades of Greed release in February.

Read more

Hytale Now Playable on Steam Deck via Linux Installer

Hytale can now run on Steam Deck using its Linux installer, enhancing compatibility for portable gaming.

Read more