LnkMeMaybe - A Review of CVE-2026-25185
ID: 93b571c4-c156-5f78-8e3c-5becf39dcf2f
STIX ID: report--93b571c4-c156-5f78-8e3c-5becf39dcf2f
Feed Name: TrustedSec blog
A research post and accompanying C# tooling that reverse-engineers Windows .lnk shortcut internals and documents discovery of CVE-2026-25185: a parsing bug where DARWIN and ICON_ENVIRONMENT_PROPS ExtraData blocks trigger PathFileExistsW on an expanded path during .lnk preview, enabling outbound authentication and credential relay. The write-up includes analysis of .lnk structures, PoC/CLI/UI tools to generate malicious .lnk files, affected Windows components (indexing service, Defender), and a disclosure timeline culminating in a March 10, 2026 patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
