Bleepingcomputer
Microsoft Mitigates Windows LNK Vulnerability Exploited in Zero-Day Attacks
First seen 3 Dec 2025, 17:41 UTC
•

•48.0
Export
Article Content
Browse articles
Microsoft has mitigated a high-severity Windows LNK vulnerability, tracked as CVE-2025-9491, which has been exploited by state-backed and cybercrime groups in zero-day attacks. This flaw allows attackers to hide malicious commands within LNK files, requiring user interaction to execute the attacks. Despite the mitigation, the vulnerability remains unpatched, posing ongoing risks to users.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
ScarCruft's Supply-Chain Attack Targets Yanbian Gaming Platform with BirdCall Malware
New NarwhalRAT Malware Targets Korean Users via Phishing Emails
APT37 Launches Targeted Cyberattack Using Social Media and Tampered Software
North Korean Konni Group Uses KakaoTalk for Malware Distribution in Spear-Phishing Campaign