VulnerAlert



DATABASE
MICROSOFT
03-12-2025 14:58
Tags
#hacker
#exploit
#data
#windows
#html
#microsoft
#database
#vulnerability
#threat
#security
#remote
#patch
#malicious
#flaw
#execution
#execute
#attack
Descripción
Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation Microsoft has silently plugged a security flaw that been exploited by several threat actors since 2017 as part the company's November 2025 Patch Tuesday updates , according to ACROS Security's 0patch . The vulnerability in question is CVE-2025-9491 (CVSS score: 7.8/7.0), which described Shortcut (LNK) file UI misinterpretation could lead remote code execution. "The specific exists within handling .LNK files," description NIST National Vulnerability Database (NVD). "Crafted data an can cause hazardous content be invisible user who inspects via Windows-provided interface. An attacker leverage this execute context current user." In other words, these shortcut files are crafted such viewing their properties conceals malicious commands executed them out u... https://thehackernews.com/2025/12/microsoft-silently-patches-windows-lnk.html
Link externo
Ver detalles

Fuente
https://thehackernews.com/2025/12/microsoft-silently-patches-windows-lnk.html
Resultados similares
Coincidentes en almenos en 50% de los tags
07-03-2026 CVE-2026-30822
Flowise is a drag & drop user interface to build a customized large language model flow. Prior ...
Ver información
06-03-2026 CVE-2026-28681
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por