Junglewise Threat Intelligence

CVE-2025-33053: Microsoft Windows remote code execution in Internet Shortcut files

CVE-2025-33053 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-06-10

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A critical vulnerability in Microsoft Windows allows attackers to remotely execute malicious code on a victim's computer. This occurs when a user opens a specially crafted Internet Shortcut file that points to a malicious remote server. This flaw has been actively exploited in the wild by sophisticated threat actors to compromise systems and deploy malware.

Technical details

This vulnerability (CWE-73) exists in how Microsoft Windows handles Internet Shortcut (.url) files. An attacker can craft a shortcut file where the 'WorkingDirectory' attribute points to a remote WebDAV location. When a user interacts with the file, Windows attempts to access the remote path, which can be leveraged to execute arbitrary code. The attack requires minimal user interaction (opening the file) and can be delivered via email or web downloads. Microsoft released patches for this zero-day vulnerability in June 2025 following reports of active exploitation by the 'Stealth Falcon' threat group.

Affected products

  • Microsoft Windows Windows 10, Windows 11, Windows Server 2008, 2012, 2016, 2019, 2022

Timeline

  • 2025-06-10: disclosed
  • 2025-06-10: patched
  • 2025-06-10: kev added: Added to CISA KEV catalog due to active exploitation.

Related threats