logo

Microsoft mitigates Windows LNK flaw exploited as zero-day

ID: 41345056-c124-5bbe-9a53-06ee91fb2e6d

STIX ID: report--41345056-c124-5bbe-9a53-06ee91fb2e6d

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-12-03

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

A high-severity Windows LNK zero-day (CVE-2025-9491) has been exploited in the wild by numerous state-backed and cybercrime groups to hide malicious command arguments in .lnk shortcuts and deploy malware (Ursnif, Gh0st RAT, Trickbot, PlugX, etc.). Trend Micro and Arctic Wolf reported widespread exploitation across campaigns targeting diplomats and other victims; Microsoft appears to have silently mitigated display behavior in updates rather than issuing a full patch, and ACROS/0patch released an unofficial micropatch while the underlying attack vector requiring user interaction remains exploitable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.