Microsoft has silently patched an LNK bug that has been exploited by various malicious actors since 2017, as part of the November 2025 Patch Tuesday updates, according to ACROS Security and 0patch.
See also: Microsoft investigates Defender Portal access issues

The vulnerability in question is CVE-2025-9491 (CVSS score: 7.8/7.0), which is described as a Windows shortcut (LNK) file user interface interpretation error that could lead to remote code execution.
This particular flaw exists in the handling of .LNK files. Crafted data in a .LNK file could make malicious content in the file invisible to a user inspecting the file through the user interface provided by Windows. An attacker could exploit this vulnerability to execute code in the context of the current user.
In other words, these shortcut files are crafted so that viewing their properties in Windows hides the malicious commands they execute, using various “white space” characters. To trigger their execution, attackers could disguise the files as harmless documents.
Details of the vulnerability first emerged in March 2025, when Trend Micro's Zero Day Initiative (ZDI) revealed that the issue had been exploited by 11 state-run groups from China, Iran, North Korea, and Russia in data theft, espionage, and financially motivated campaigns, some of which date back to 2017. The issue is also being tracked as ZDI-CAN-25373.
At the time, Microsoft stated that the bug did not meet the threshold for immediate service and that it would consider fixing it in a future release. It also noted that the LNK file format is blocked in Outlook, Word, Excel, PowerPoint, and OneNote, resulting in any attempt to open such files triggering a warning to users not to open files from unknown sources.
See also: Microsoft improves and destroys the dark theme

A report from HarfangLab then found that the LNK bug had been abused by a cyberespionage group known as XDSpy to distribute a Go-based malware called XDigo, in attacks targeting Eastern European government entities, the same month the bug was publicly disclosed.
Then, in late October 2025, the issue surfaced for a third time after Arctic Wolf flagged an offensive campaign in which China-linked threat actors exploited the flaw in attacks targeting European diplomatic and government entities and delivered the PlugX.
This development prompted Microsoft to issue official guidance on CVE-2025-9491, reiterating its decision not to patch it and emphasizing that it does not consider it a vulnerability “due to user interaction and the fact that the system already warns users that this format is not trusted.”
0patch stated that the bug is not just about hiding the malicious part of the command outside the Target field, but the fact that an LNK file allows the Target arguments to be a very long string (tens of thousands of characters), while the Properties dialog only displays the first 260 characters, silently truncating the rest.
This means that a malicious actor could create an LNK file that could execute a long command, which would only cause the first 260 characters of the command to be displayed to a user who viewed its properties. The rest of the command string is simply truncated. According to Microsoft, the file structure theoretically allows strings of up to 32k characters.
See also: Vulnerability in Microsoft Azure API Management bypasses administrator restrictions

The silent fix released by Microsoft addresses the issue by showing the entire Target command with arguments in the Properties dialog box, regardless of its length. However, this behavior is dependent on the ability to have shortcut files with more than 260 characters in the Target field.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
