ZeroHour

CVE-2017-8464

KEV PoC ×2mass1

Remote Code Execution in Microsoft Windows Shell via crafted .LNK shortcuts

CISA: Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
90%p100
Published
()
KEV added
AI analysis

CVE-2017-8464 is a remote code execution flaw in how the Windows Shell handles .LNK shortcut files, evoking the 2010 Stuxnet-era LNK bug that Microsoft had to fix repeatedly. It is triggered when Windows Explorer, or any other application that parses shortcut icons, processes a crafted .LNK file — for example while browsing a USB drive, network share, or downloaded folder — and the CVSS vector requires user interaction but no privileges. A successful attacker can execute arbitrary code in the context of the logged-on user, with high impact on confidentiality, integrity, and availability. Nearly every Windows release in support at disclosure time is affected, spanning Windows 7 SP1, Windows 8/8.1, Windows RT 8.1, Windows 10 (Gold through 1703), and Windows Server 2008 through 2016. Exploitation is confirmed: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-10, EPSS assigns a 90% 30-day exploitation probability (100th percentile), public PoCs exist, and headlines tie it to malware campaigns such as Lucifer and BlackSquid.

What to do: Apply Microsoft security updates per vendor instructions (released with the June 2017 Patch Tuesday and carried forward in later cumulative/rollup updates) on all affected systems, prioritizing legacy Windows 7/8/RT 8.1 and Server 2008/2012/2016 hosts that remain in service, including any under Extended Security Updates. Since CISA lists this as actively exploited, verify patch status fleet-wide and hunt for suspicious .LNK activity; as interim mitigation, be cautious with untrusted removable media, network shares, and downloaded shortcuts, and consider Microsoft's guidance on disabling shortcut icon display.

Affected
Microsoft Windows 7SP1
Microsoft Windows 8Gold (RTM)
Microsoft Windows 8.1all listed
Microsoft Windows RT 8.1all listed
Microsoft Windows 10Gold (1507), 1511, 1607, 1703
Microsoft Windows Server 2008SP2; R2 SP1
Microsoft Windows Server 2012Gold; R2
Microsoft Windows Server 2016all listed
Estimated exposure
masshundreds of millions of Windows devices — The affected set spans nearly the entire global Windows installed base at disclosure (Windows 7, 8.1 and early Windows 10 alone ran on hundreds of millions of PCs, plus a large share of internet-exposed Windows servers), so exposure is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka "LNK Remote Code Execution Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1511, windows 10 1607, windows 10 1703, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news