Microsoft Windows LNK CVE-2017-8464 Remote Code Execution Vulnerability
by CIRT Team
Description: Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka “LNK Remote Code Execution Vulnerability.”
Impact: Successful exploits will allow an attacker to execute arbitrary code on the target system. Failed attacks will cause denial of service conditions.
Mitigation: Updates are available. Please check specific vendor advisory for more information.
Reference URL’s:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8464
- http://www.securityfocus.com/bid/98818/info
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8464
Recommended Posts
Active Exploitation of Critical F5 BIG – IP Vulnerability (CVE–2023-46747) Uncovered in Bangladesh
06 Nov 2024 - Security Advisories & Alerts