Microsoft Fixes LNK Vulnerability Exploited Since 2017

03 Dec 2025

Microsoft has addressed a long-standing security vulnerability, CVE-2025-9491, affecting Windows LNK files, with the November 2025 update. The flaw had been exploited by state-sponsored groups since 2017.

Security Vulnerability Details

The CVE-2025-9491 vulnerability, with a CVSS score of 7.8, involved the Windows Shortcut (LNK) file format. Manipulated LNK files could hide malicious commands, allowing attackers to execute remote code. The Windows Properties dialog previously failed to display these hidden commands, affecting user security.

  • Microsoft addressed the issue in the November 2025 update.
  • The flaw had been exploited by 11 state-sponsored groups.
  • Exploits were reported in espionage and data theft campaigns.

Security researcher 0patch pointed out the complexity of the issue involving long strings in LNK files, which were not fully visible in the Properties dialog.

Response to Exploitation

Trend Micro's Zero Day Initiative disclosed the issue in March 2025, revealing exploits by groups from China, Iran, North Korea, and Russia. These attacks targeted government entities in Eastern Europe using the XDigo malware and the PlugX backdoor.

The disclosure led to heightened scrutiny, although Microsoft initially did not consider the flaw urgent enough for immediate servicing. However, the recent silent patch now shows the entire Target field in the Properties dialog regardless of length.

Preventative Measures

Microsoft's update changes the display of command arguments, effectively closing the vulnerability's exploitation path. Security firm 0patch also released a micropatch that warns users of LNK files with over 260 characters, adding preventive security measures for users.

This patching effort reflects increased pressure on software firms to proactively address vulnerabilities before they can be widely exploited. It highlights the balance between immediate versus strategic security fixes in the fast-moving threat landscape.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6744865
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1430899
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
578497
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
463620
downloads

News and reviews for Desktop Windows

Helldivers 2 Install Size Reduced to 23GB in Beta

Arrowhead optimizes Helldivers 2 on PC, reducing installation size from 154GB to 23GB. New beta shows improved load speeds and space efficiency.

Read more

Prologue Expands with Three DLCs but No Wildlife

Prologue creator Brendan Greene confirms three new DLCs, focusing on game depth but ruling out animal additions.

Read more

Destiny 2's Renegades Expansion Boosts Player Count on Steam

Destiny 2's Renegades expansion led to a player spike on Steam. Despite Star Wars themes, numbers remain below past peaks.

Read more

Microsoft Fixes LNK Vulnerability Exploited Since 2017

Microsoft patched the long-standing LNK security flaw in Windows as part of the November 2025 update, impacting user security.

Read more

Highlights from PC Gaming Show: Most Wanted 2025 Countdown

PC Gaming Show: Most Wanted 2025 on December 4 reveals top PC games with new trailers and announcements. Anticipated by gamers and industry experts.

Read more

Microsoft Alters LNK File Behavior to Tackle Vulnerability

Microsoft changes LNK file handling in response to exploited vulnerability CVE-2025-9491, affecting multiple cybercrime groups.

Read more

Norsca Rework Highlights Tides of Torment Expansion

Tides of Torment expansion releases 2023-12-04, with Norsca rework featuring new units and mechanics for Sayl the Faithless.

Read more

Microsoft Ad Promotes Copilot, Sparks Mixed Reactions

Microsoft released a Windows 11 ad featuring Copilot, aiming to showcase advanced voice integration. The ad has sparked mixed reactions, potentially inflating expectations.

Read more

Windows Accessibility Upgrades Enhance User Experience

Windows enhances accessibility with new voice and dictation features, benefiting diverse user needs in 2025.

Read more

Helldivers 2 Trims PC Install Size by 85%

Helldivers 2's PC install size reduced to 23 GB from 154 GB, thanks to deduplication efforts by Arrowhead Game Studios and Nixxes Software.

Read more