logo

Microsoft quietly shuts down Windows shortcut flaw after years of espionage abuse

ID: d64d0f25-13c6-5c26-9763-f41ffb8d9acd

STIX ID: report--d64d0f25-13c6-5c26-9763-f41ffb8d9acd

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-12-04

Date Updated: 2026-04-26

Author: Carly Page

...
...

Microsoft quietly mitigated CVE-2025-9491, a Windows .lnk shortcut parsing flaw long abused to hide malicious command-line arguments and enable hidden code execution. The vulnerability has been exploited since 2017 by multiple state-sponsored and criminal groups—most recently UNC6384/Mustang Panda—to deploy PlugX via obfuscated PowerShell and DLL sideloading against European diplomatic targets; Microsoft added a silent mitigation in November 2025, but many systems may remain unpatched and at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.