Executive brief
Windows Shell fails to properly handle crafted .LNK files during icon display. An attacker can execute arbitrary code when Windows Explorer or any application parses the icon of a malicious shortcut file.
Affected products
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8 Gold
- Microsoft Windows 8.1 -
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows RT 8.1 -
- Microsoft Windows 10 Gold, 1511, 1607, 1703
- Microsoft Windows Server 2016 -
Timeline
- 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-02-10: disclosed