Microsoft’s recent Windows update released in April 2025 has introduced an unexpected and somewhat controversial element to the Windows file system: an empty folder named "inetpub" appearing on many user systems. This update, part of Windows 11 24H2 and Windows 10 cumulative patches (notably...
cve-2025-21204
cybersecurity alerts
directory hijacking
directory junction
directory junctions
filesystem security
inetpub folder
it administration
it security news
microsoft patch
microsoft updates
mklink utility
patch management
security patch
security patches
securityresearchersecurity vulnerability
symlink attack
symlink security
system administration
system folder security
system security
system security best practices
update risks
windows 10
windows 11
windows 2025 update
windows iis
windows process activation
windows security
windows system files
windows system folders
windows update
windows update patch
windows vulnerabilities
windows vulnerabilities mitigation
Here is a summary of the original Petri article on the Windows 11 'inetpub' folder security risk:
What happened?
After the April 2025 Patch Tuesday update, a new "inetpub" folder started appearing on Windows 10 and 11 machines.
Microsoft created this folder to help patch a bug (CVE-2025-21204)...
admin tips
cve-2025-21204
cyberattack prevention
cybersecurity
cybersecurity best practices
directory junction
directory junctions
folder permissions
inetpub folder
insider threat
it protection
it security
junction points
malware risk
microsoft april 2025 update
microsoft patch
microsoft security
microsoft updates
operating system securitysecurity alerts
security mitigation
security patch
securityresearchersecurity vulnerability
symbolic links
symlink exploitation
symlink vulnerability
symlinks
sysadmin guide
system integrity
system permissions
system protection
system security
system vulnerabilities
update security
windows 11
windows defender
windows folder permissions
windows iis
windows patch
windows security
windows security patch
windows security risk
windows servicing stack
windows system administration
windows system risks
windows update
windows update management
windows update security
windows update vulnerability
windows updates
windows vulnerabilities
windows vulnerability
At Black Hat USA each year, we unveil the Top 100 Security Researcher list to reflect the amazing engagement we get from the community. During this period, we had several thousand researchers engage with the Microsoft Security Response Center (MSRC). We appreciate all the partnership and...
acknowledgements
annual report
august 2018
black hat usa
bounty for defense
community engagement
cybersecurity
industry collaboration
microsoft
mitigation bounty
msrc
research impact
research methods
research recognition
researchers
security impact
securityresearcher
severity
top 100
vulnerabilities
Criminal Hacker "Iceman" gets 13 years. Former "Security Researcher- Max Butler" has been sentenced to 13 years for hacking into a financial institutions and stealing credit card account numbers.