CVE-2025-9491
HIGH EXPLOITEDWindows 11 23H2 - Remote Code Execution via LNK File UI Misrepresentation
Title source: llmExploitation Summary
CVE-2025-9491 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Amperclock.
AI-analyzed exploit summary This repository contains a functional proof-of-concept tool for CVE-2025-9491, a Windows LNK file obfuscation vulnerability. The tool allows creation, obfuscation, and parsing of LNK files to hide malicious command-line arguments using whitespace padding.
Description
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of .LNK files. Crafted data in an .LNK file can cause hazardous content in the file to be invisible to a user who inspects the file via the Windows-provided user interface. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25373.
Exploits (1)
This repository contains a functional proof-of-concept tool for CVE-2025-9491, a Windows LNK file obfuscation vulnerability. The tool allows creation, obfuscation, and parsing of LNK files to hide malicious command-line arguments using whitespace padding.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H