top of page
perceptive_background_267k.jpg

Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation

Published:

3 December 2025 at 17:46:36

Alert date:

5 December 2025 at 08:03:22

Source:

thehackernews.com

Click to open the original link from this advisory

Microsoft silently patched CVE-2025-9491, a Windows Shortcut (LNK) file UI misinterpretation vulnerability with a CVSS score of 7.8/7.0 that has been actively exploited by threat actors since 2017. The flaw was addressed as part of Microsoft's November 2025 Patch Tuesday updates. The vulnerability could lead to remote code execution through malicious LNK files that misrepresent their actual target to users. Multiple threat actors have been leveraging this flaw for years before Microsoft finally addressed it. ACROS Security's 0patch reported on the silent fix by Microsoft.

Technical details

Mitigation steps:

Affected products:

Windows

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page