[CIVN-2025-0351] Remote Code Execution Vulnerability in Microsoft Windows LNK

By Published On: December 4, 2025

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Remote Code Execution Vulnerability in Microsoft Windows LNK 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Microsoft Windows
Overview
A vulnerability has been reported in Microsoft Windows, which may allow a remote attacker to execute arbitrary code on the targeted vulnerable system.
Target Audience:
All end-user organizations and individuals using the affected Windows installations.
Risk Assessment:
High risk of arbitrary code execution, privilege escalation, and persistence.
Impact Assessment:
Potential for full system compromise, sensitive information disclosure, and deployment of malware.
Description
The vulnerability exists in Windows due to improper handling of .lnk shortcut files. An attacker could exploit this vulnerability by getting a user to open a malicious .lnk file, typically shared inside an archive file. The flaw allows the shortcut to hide malicious command-line arguments, leading the user to unknowingly execute harmful code.
Successful exploitation could allow a remote attacker to execute arbitrary code on the targeted system.
Solution
 
https://msrc.microsoft.com/update-guide/advisory/ADV25258226
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/advisory/ADV25258226
References
 
https://www.zerodayinitiative.com/advisories/ZDI-25-148/
CVE Name
CVE-2025-9491
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmkxjvEACgkQ3jCgcSdc
ys/Znw//XfmkdYLkH9IA06SwXQz26u8+XbImWBZyOEZKkvm1KA4z8lMCLFmAnUlN
OKUEOuaTJe5wtQQ83vu0k1MXQhS5ccmWCKokzAJLGakbWJ2x1ybruYv3gBMxquwu
wWvV3raKe4wYLvCH3D+3pUQlU8PQCtIpOXbCmtRpB+CEfT/cL1D4vGRA2lKKuvNp
Op0hbh+njQiqEZ0dGAcgnHI//JKkdtWw5tb1NshpAvrkwPU/yMuVWcKGbI1dUOfm
eDlBSuQ6uYL7bMI4z7I8lQx8lzFhKdWMXE7YZbMyaDL4lt+EBZhj6ZcvbErT7izp
cZpCESeZJLpX9jIxxtFg9tY/WkkC86GN+MCOOH3cirtcOuaL2jyrCpx7qllWVSqA
GrpUuz43yAVpLW4d1I8PnIyqgNsqMVYEMn+s2yP2eyrm5OXGcEnY9bo/yQYQgcYc
gcoD1+nn77Xmf9rcfRD+/FP5Bq3Fmey1Hv2i5xeOl+2TU5Cy6kVeUbTn7cvmozLv
TTaZlerXW0Jb3XOtdMkfLIpt1MYoVw1q+p5ArmpdAategIxBLXUQGUfGeDCSC+dF
jz2ivbxPBt8aOUuhmlEJ6mcQC49JRkYWCx1iEmrvjVaJpcWoH6XVYBjhOPdBXpeT
txFc4LmrgN5EX4Ijb40f2ZehtKofAv8thH3wdkGU+CccYgF1Ysc=
=uFs6
—–END PGP SIGNATURE—–

Share this article