ZeroHour

CVE-2010-2568

KEVmass

Remote Code Execution in Microsoft Windows via Malicious Shortcut (LNK) Parsing

CISA: Microsoft Windows Remote Code Execution Vulnerability

CVSS
EPSS
91%p100
Published
KEV added
AI analysis

CVE-2010-2568 is an input-validation flaw (CWE-20) in how Microsoft Windows parses shortcut files, allowing malicious code to execute when the operating system merely displays the icon of a malicious shortcut (.lnk) file. Triggering requires nothing more than the Windows shell rendering the shortcut's icon — for example when browsing a folder containing the file, a vector widely abused via USB drives and network shares in incidents tied to Stuxnet and Gauss. A successful attacker gains arbitrary code execution with the privileges of the logged-on user, suitable for initial access or lateral movement. All Microsoft Windows systems as listed by CISA are affected; the provided data does not specify exact version ranges. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2022-09-15), carries a 91.3% EPSS probability of exploitation (100th percentile), and related headlines report Microsoft having to re-issue the fix more than once for Stuxnet-related attacks.

What to do: Apply Microsoft updates per vendor instructions (CISA's required action); since headlines indicate this LNK fix was re-released multiple times, verify systems carry the latest cumulative Windows updates rather than only the original patch. Until patched, avoid browsing untrusted removable drives or network shares with a shell that renders shortcut icons, and monitor for LNK-delivered malware.

Affected
Microsoft Windows
Estimated exposure
mass≈1 billion+ Windows installations worldwide (unknown share unpatched; legacy versions carry the highest risk) — Windows runs on well over a billion active devices globally and the flawed shortcut-parsing behavior exists across the broadly deployed Windows versions CISA lists, so exposure is effectively the entire Windows install base, with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Windows
Weakness
CWE-20

In the news