Executive brief
Windows Shell incorrectly parses .LNK and .PIF shortcut files during icon display in Windows Explorer. This allows local or remote attackers to execute arbitrary code with the privileges of the logged-on user when the malicious shortcut is viewed.
Affected products
- Microsoft Windows XP SP3
- Microsoft Windows Server 2003 SP2
- Microsoft Windows Vista SP1
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2
- Microsoft Windows Server 2008 R2
- Microsoft Windows 7
Timeline
- 2010-07: exploited: Demonstrated in the wild and leveraged by malware targeting Siemens WinCC SCADA systems.
- 2022-09-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2010-08-02: patched: Microsoft addressed the issue in security bulletin MS10-046.