Skip to main content

Microsoft to Patch Shortcut Zero-Day Exploit

Image used with permission by copyright holder

Microsoft has announced it plans to break from its normal monthly schedule of security updates to issue an immediate patch for a critical zero-day vulnerability in the way the Windows Shell handles shortcut files. According to Microsoft, the exploit first appeared in the wild on July 16, and at that time targets were limited, but have been escalating in recent days.

“We are releasing the bulletin as we’ve completed the required testing and the update has achieved the appropriate quality bar for broad distribution to customers,” Microsoft senior security response communications manager Christopher Budd wrote in the company’s security response blog. “Additionally, we’re able to confirm that, in the past few days, we’ve seen an increase in attempts to exploit the vulnerability. We firmly believe that releasing the update out of band is the best thing to do to help protect our customers.”

The problem lies in the way Windows handles some .LNK shortcuts, particularly for icons on the desktop: the Windows Shell is not properly validating .LNK files in all cases.

Microsoft has been struggling with the security community in recent months, as an increasingly number of serious vulnerabilities have been revealed with giving Microsoft much advance warning; earlier this month, a group of security researchers actually vowed to look for Windows exploits and take them public without first sharing them with Microsoft at all. Microsoft has since extended an olive branch, announcing last week a new “coordinated vulnerability disclosure” process it hopes will address dissatisfaction in the broader security community.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
How to take a screenshot using a Microsoft Surface
A 2017 Microsoft Surface Pro on a table.

Whether you want to capture friends and relatives making funny faces on Skype or need accessible photos of online resources or programs, screenshots benefit users in many ways. Since the Surface Pros are a bit different than other 2-in-1 laptops, however, you may find yourself wondering how to take a screenshot on one. Here, we take the mystery out of the

Read more
Microsoft may fix the most frustrating thing about Windows updates
Windows 11 updates are moving to once a year.

Most Windows users will agree that one of the most annoying things about the operating system is the updates. While Windows Updates are necessary, they often tend to come up at the worst possible time, interrupting work and gaming sessions with persistent reminders that the system needs to reboot. Microsoft might be fixing that problem in the upcoming Windows 11 24H2 build, but it's still too early to bid farewell to those ill-timed reboots.

As spotted in the latest Windows 11 Insider Preview Build 26058, Microsoft is testing "hot patching" for some Windows 11 updates. Hot patching refers to a dynamic method of updating that often doesn't change the software version and may not even need a restart. In the context of Windows 11, it's pretty straightforward -- Windows will install the update, and you won't have to reboot your system.

Read more
7 beloved Windows apps that Microsoft has killed over the years
A screenshot of Internet Explorer 9.

Microsoft's history is littered with the discontinuation of once-beloved applications. Most recently, WordPad, the renowned text editor app, was conspicuously absent from the latest beta build of Windows 11, indicating an end to its 28-year-long journey. I have fond memories of using the app back in my college days when Microsoft Office was too pricey for me.

WordPad is far from the only app to get canceled by Microsoft over the years. From pioneering productivity tools to nostalgic multimedia players, let's reminisce about some of the most famous applications that Microsoft has consigned to the annals of tech history.
Internet Explorer

Read more