logo

No, it’s not OK to delete that new inetpub folder

ID: 1c58bdbe-18e0-58b0-9319-e2ed2d46b032

STIX ID: report--1c58bdbe-18e0-58b0-9319-e2ed2d46b032

Feed Name: Malwarebytes Blog

Threat Score
45/100

Date Published: 2025-04-14

Date Updated: 2026-04-28

...
...

Microsoft released a patch for CVE-2025-21204, a "link following" vulnerability in the Windows Update Stack that can allow an authenticated attacker to perform file operations as NT AUTHORITY\SYSTEM. Applying the update creates a %systemdrive%\inetpub folder as a mitigation and Microsoft warns users not to delete it; the update aims to prevent attackers from replacing files with links or shortcuts that resolve to unintended resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.