• News/
  • https://www.theregister.com/2025/03/18/microsoft_trend_flaw/

Microsoft isn't fixing 8-year-old zero day used for spying

The Register
·
Iain Thomson
·
Published Mar 18, 2025
·
Updated

An exploitation avenue found by Trend Micro in Windows has been used in an eight-year-long spying campaign, but there's no sign of a fix from Microsoft, which apparently considers this a low priority. The attack method is low-tech but effective, relying on malicious .LNK shortcut files rigged with commands to download malware. While appearing to point to legitimate files or executables, these shortcuts quietly include extra instructions to fetch or unpack and attempt to run malicious payloads. Ordinarily, the shortcut's target and command-line arguments would be clearly visible in Windows, making suspicious commands easy to spot. But Trend's Zero Day Initiative said it observed North Korea-backed crews padding out the command-line arguments with megabytes of whitespace, burying the actual commands deep out of sight in the user interface. Trend reported this to Microsoft in September last year and estimates that it has been used since 2017. It said it had found nearly 1,000 tampered .LNK files in circulation but estimates the actual number of attacks could have been higher. "This is one of many bugs that the attackers are using, but this is one that is not patched and that's why we reported it as a zero day," Dustin Childs, head of threat awareness at the Zero Day Initiative, told The Register. "We told Microsoft but they consider it a UI issue, not a security issue. So it doesn't meet their bar for servicing as a security update, but it might be fixed in a later OS version, o...

Read full article

Affected Software

2 affected components
Microsoft Windows
Microsoft Windows
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses an eight-year-old zero-day vulnerability in Microsoft Windows that has been exploited for espionage and remains unaddressed by Microsoft.

2

What security implications are discussed?

The article highlights the ongoing risk of a zero-day vulnerability that allows for long-term spying without any remediation from Microsoft.

3

What products or software are affected?

The affected product is Microsoft Windows, which is vulnerable to the identified zero-day exploitation.

4

How long has the spying campaign been ongoing?

The spying campaign utilizing this zero-day vulnerability has been ongoing for eight years.

5

What is Microsoft's response to the vulnerability?

Microsoft has deemed the vulnerability a low priority and has not provided a fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203