CVE-2025-9491
massLNK File UI Misrepresentation RCE in Microsoft Windows
CVE-2025-9491 is a user-interface misrepresentation flaw (CWE-451) in Microsoft Windows' handling of .LNK shortcut files: crafted data in an .LNK file can make hazardous content invisible when a user inspects the file through the Windows-provided UI. Exploitation requires user interaction — the target must visit a malicious page or open a malicious file — after which the disguised shortcut causes code execution. A successful attack lets the attacker run arbitrary code in the context of the current user, with no privilege escalation indicated (CVSS 4.0 base score 4.6, local attack vector). The CPE data lists Windows 11 23H2 as the affected product, though the advisory text describes Microsoft Windows generally; no affected build numbers are provided. Exploitation is not hypothetical: reporting indicates Microsoft silently patched the flaw after years of active exploitation, APT groups continue leveraging it, EPSS assigns a 68.9% probability of exploitation within 30 days (99th percentile), and it is not yet in CISA KEV.
What to do: Ensure Windows endpoints are fully patched with the Microsoft update that fixes .LNK file rendering — verify fleet-wide build levels through Windows Update or your patch-management tooling, since the fix was reportedly shipped silently. Until patched, treat .LNK files arriving via email, web downloads, or removable USB media with suspicion and do not rely on visual inspection of shortcut properties as a safety check. Given reported APT abuse, prioritize detection of malicious .LNK delivery in targeted sectors (government, power) named in current threat reporting.
| Microsoft Windows 11 23H2 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of .LNK files. Crafted data in an .LNK file can cause hazardous content in the file to be invisible to a user who inspects the file via the Windows-provided user interface. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25373.
- Vendors
- microsoft
- Products
- windows 11 23h2
- Weakness
- CWE-451
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X