Microsoft Patched Windows LNK Vulnerability Abused by Hackers to Hide Malicious Code
Microsoft has addressed the Windows shortcut vulnerability identified as CVE-2025-9491 . This vulnerability, exploited by threat actors since 2017, was patched in the November 2025 Patch Tuesday updates but was not prominently listed among the officially…
Microsoft has addressed the Windows shortcut vulnerability identified as CVE-2025-9491 . This vulnerability, exploited by threat actors since 2017, was patched in the November 2025 Patch Tuesday updates but was not prominently listed among the officially patched vulnerabilities.
The issue was initially reported on March 18, 2025, when researchers from Trend Micro's Zero Day Initiative, Peter Girnus, and Aliakbar Zahravi, published their findings. They identified nearly 1,000 malicious Windows shortcut (.lnk) files exploiting this flaw across various offensive campaigns dating back to 2017.
The vulnerability allowed attackers to create shortcut files that concealed malicious commands by displaying only the first 260 characters of the Target field in the Properties dialog.
Microsoft initially declined to patch this issue after being notified in September 2024, citing that it did not meet their servicing threshold and that existing security warnings provided adequate protection through the Mark of the Web feature.
Microsoft has addressed the Windows shortcut vulnerability identified as CVE-2025-9491 .
In October 2025, research from Arctic Wolf highlighted active exploitation of this vulnerability by threat actor UNC6384, targeting Hungarian and Belgian diplomatic entities. The attackers used PlugX malware, leveraging the UI misrepresentation flaw to hide malicious PowerShell commands.
Despite in-the-wild exploitation, Microsoft issued Advisory ADV25258226, maintaining that due to user interaction and existing warnings about untrusted formats, this was not considered a vulnerability.
In November 2025, Microsoft updated how Windows displays LNK file properties. The Properties dialog now shows the entire Target command, although in a single-line field requiring text selection to view completely. This change was not acknowledged in the official patch documentation.
ACROS Security developed an alternative patch that truncates any LNK file Target field exceeding 260 characters and alerts users to suspicious activity. This solution aims to block the malicious shortcuts identified by Trend Micro while preserving functionality for legitimate shortcuts.
Security experts recommend enhancing endpoint detection capabilities and conducting security awareness training to identify suspicious shortcut files, especially those received via email or downloaded from untrusted sources.
Based on reporting by Cyber Security News.
