CVE-2025-9491
HIGH EXPLOITEDWindows 11 23H2 - Remote Code Execution via LNK File UI Misrepresentation
Title source: llmExploitation Summary
CVE-2025-9491 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Amperclock, HORKimhab.
AI-analyzed exploit summary This repository contains a functional proof-of-concept tool for CVE-2025-9491, a Windows LNK file obfuscation vulnerability. The tool allows creation, obfuscation, and parsing of LNK files to hide malicious command-line arguments using whitespace padding.
Description
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of .LNK files. Crafted data in an .LNK file can cause hazardous content in the file to be invisible to a user who inspects the file via the Windows-provided user interface. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25373.
Exploits (2)
This repository contains a functional proof-of-concept tool for CVE-2025-9491, a Windows LNK file obfuscation vulnerability. The tool allows creation, obfuscation, and parsing of LNK files to hide malicious command-line arguments using whitespace padding.
The repository contains only a markdown file with a high-level description of CVE-2025-9491 (Windows LNK UI misrepresentation RCE) but no actual exploit code. It links to external GitHub and encrypted archive sources, which is a common social engineering tactic to lure researchers into downloading untrusted content.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H