Microsoft has quietly closed off a critical Windows shortcut file bug long abused by espionage and cybercrime networks. The flaw, tracked as CVE-2025-9491, allows malicious .lnk shortcut files to hide harmful command-line arguments from users, enabling hidden code execution when a victim opens the shortcut. Researchers at Trend Micro said in March that nearly a thousand malicious .lnk samples dating back to 2017 exploited this weakness across a mix of state-sponsored and cybercriminal campaigns worldwide. "Our analysis revealed that 11 state-sponsored groups from North Korea, Iran, Russia, and China have employed ZDI-CAN-25373 in operations primarily motivated by cyber espionage and data theft," it said at the time. The trick is deceptively simple: malicious commands are padded with whitespace (or other non-printing characters) so that when the shortcut's properties are viewed in Windows, the "Target" field appears harmless – blank or ending in innocuous binaries – effectively concealing nefarious payloads. Initial attempts by Trend Micro's Zero Day Initiative (ZDI) to get the flaw patched were rebuffed by Microsoft, which argued that the flaw was "low severity" and did not meet the bar for servicing. But the window of complacency has now closed. According to patch-watcher 0patch, Microsoft rolled out a "silent mitigation" in its November 2025 Patch Tuesday fix bundle. Post-update, Windows' "Properties" dialog now reveals the full command, shutting down the obfuscation trick ...
Microsoft fixes Windows shortcut flaw exploited for years
The Register
·Carly Page
·Published Dec 4, 2025
·Updated
Affected Software
1 affected component
Microsoft Windows
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Microsoft fixing a critical vulnerability in Windows shortcut files known as CVE-2025-9491.
2
What security implications are discussed?
The flaw allows malicious .lnk files to hide harmful command-line arguments, posing risks of espionage and cybercrime.
3
What software is affected by this vulnerability?
The critical vulnerability affects Microsoft Windows operating systems.
4
How long has the Windows shortcut flaw been exploited?
The article indicates that the vulnerability has been abused for years by various cybercriminal and espionage groups.
5
What steps has Microsoft taken to address this issue?
Microsoft has quietly implemented a fix to close off the critical Windows shortcut file bug.