You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
zdi-can-25373
About this tag
ZDI-CAN-25373 is a Windows zero-day vulnerability tracked by Trend Micro that has been exploited by nation-state hackers since 2017. The flaw manipulates how Windows handles shortcut (.lnk) files, enabling covert attacks. Despite active exploitation, Microsoft has stated the bug does not meet its bar for servicing and has not issued an immediate patch. This tag covers discussions about the vulnerability's mechanics, its decade-long exploitation history, and Microsoft's response. It is relevant for security researchers, IT administrators, and Windows users concerned about unpatched exploits and nation-state threat actors targeting Windows systems.
Nation-state hackers have been quietly exploiting a Windows vulnerability since 2017, leaving many organizations exposed to covert attacks. At the center of this drama is a zero-day flaw, tracked by Trend Micro as ZDI-CAN-25373, which manipulates how Windows handles shortcut (.lnk) files. While...