logo

LnkMeMaybe - A Review of CVE-2026-25185

ID: 93b571c4-c156-5f78-8e3c-5becf39dcf2f

STIX ID: report--93b571c4-c156-5f78-8e3c-5becf39dcf2f

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2026-03-13

Date Updated: 2026-05-01

...
...

A research post and accompanying C# tooling that reverse-engineers Windows .lnk shortcut internals and documents discovery of CVE-2026-25185: a parsing bug where DARWIN and ICON_ENVIRONMENT_PROPS ExtraData blocks trigger PathFileExistsW on an expanded path during .lnk preview, enabling outbound authentication and credential relay. The write-up includes analysis of .lnk structures, PoC/CLI/UI tools to generate malicious .lnk files, affected Windows components (indexing service, Defender), and a disclosure timeline culminating in a March 10, 2026 patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.