CVE-2025-9491: Windows LNK Flaw Exploited Since 2017—Microsoft Won't Patch
CVE-2025-9491 (aka ZDI-CAN-25373) is a Windows LNK file vulnerability that state actors have quietly exploited since at least 2017. The technique is elegant: attackers embed command-line arguments in …
Category: Vulnerabilities / Microsoft / Microsoft