CVE-2025-9491

HIGH EXPLOITED

Windows 11 23H2 - Remote Code Execution via LNK File UI Misrepresentation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-9491 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Amperclock.

AI-analyzed exploit summary This repository contains a functional proof-of-concept tool for CVE-2025-9491, a Windows LNK file obfuscation vulnerability. The tool allows creation, obfuscation, and parsing of LNK files to hide malicious command-line arguments using whitespace padding.

Description

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of .LNK files. Crafted data in an .LNK file can cause hazardous content in the file to be invisible to a user who inspects the file via the Windows-provided user interface. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25373.

Exploits (1)

nomisec WORKING POC 19 stars
by Amperclock · client-side
https://github.com/Amperclock/CVE-2025-9491_POC

This repository contains a functional proof-of-concept tool for CVE-2025-9491, a Windows LNK file obfuscation vulnerability. The tool allows creation, obfuscation, and parsing of LNK files to hide malicious command-line arguments using whitespace padding.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Windows Shortcut (LNK) files
No auth needed
Prerequisites: Python 3.7 or higher · pylnk3 library
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0091
EPSS Percentile 76.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2025-10-30
CWE
CWE-451
Status published
Products (1)
microsoft/windows_11_23h2 10.0.22631.4169
Published Aug 26, 2025
Tracked Since Feb 18, 2026