CVE-2025-9491

HIGH EXPLOITED

Windows 11 23H2 - Remote Code Execution via LNK File UI Misrepresentation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-9491 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Amperclock, HORKimhab.

AI-analyzed exploit summary This repository contains a functional proof-of-concept tool for CVE-2025-9491, a Windows LNK file obfuscation vulnerability. The tool allows creation, obfuscation, and parsing of LNK files to hide malicious command-line arguments using whitespace padding.

Description

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of .LNK files. Crafted data in an .LNK file can cause hazardous content in the file to be invisible to a user who inspects the file via the Windows-provided user interface. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25373.

Exploits (2)

nomisec WORKING POC 19 stars
by Amperclock · client-side
https://github.com/Amperclock/CVE-2025-9491_POC

This repository contains a functional proof-of-concept tool for CVE-2025-9491, a Windows LNK file obfuscation vulnerability. The tool allows creation, obfuscation, and parsing of LNK files to hide malicious command-line arguments using whitespace padding.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Windows Shortcut (LNK) files
No auth needed
Prerequisites: Python 3.7 or higher · pylnk3 library
mistral-large-3 · analyzed Feb 19, 2026 Full analysis →
github SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2025/9xxx/CVE-2025-9491.md

The repository contains only a markdown file with a high-level description of CVE-2025-9491 (Windows LNK UI misrepresentation RCE) but no actual exploit code. It links to external GitHub and encrypted archive sources, which is a common social engineering tactic to lure researchers into downloading untrusted content.

Classification
Suspicious 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Windows (unspecified version)
No auth needed
Prerequisites: User interaction (opening malicious LNK file or visiting malicious page) · Affected Windows installation
mistral-large-3 · analyzed Jul 04, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.6886
EPSS Percentile 99.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2025-10-30
CWE
CWE-451
Status published
Products (1)
microsoft/windows_11_23h2 10.0.22631.4169
Published Aug 26, 2025
Tracked Since Feb 18, 2026