CVE-2017-8464: Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka "LNK Remote Code Execution Vulnerability."
Other sources
Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8464?
CVE-2017-8464 has a severity rating of important, indicating a significant threat to affected systems.
How do I fix CVE-2017-8464?
To fix CVE-2017-8464, ensure you install the latest security updates released by Microsoft for your version of Windows.
What systems are affected by CVE-2017-8464?
CVE-2017-8464 affects various versions of Microsoft Windows, including Windows 7, 8.1, 10, and several server versions.
Can CVE-2017-8464 be exploited remotely?
Yes, CVE-2017-8464 can be exploited by remote attackers, allowing them to execute arbitrary code on affected systems.
What impact can CVE-2017-8464 have on my system?
The impact of CVE-2017-8464 can include unauthorized access and execution of arbitrary code, potentially compromising system security.