Skip to main content

Microsoft to Patch Shortcut Zero-Day Exploit

Microsoft has announced it plans to break from its normal monthly schedule of security updates to issue an immediate patch for a critical zero-day vulnerability in the way the Windows Shell handles shortcut files. According to Microsoft, the exploit first appeared in the wild on July 16, and at that time targets were limited, but have been escalating in recent days.

“We are releasing the bulletin as we’ve completed the required testing and the update has achieved the appropriate quality bar for broad distribution to customers,” Microsoft senior security response communications manager Christopher Budd wrote in the company’s security response blog. “Additionally, we’re able to confirm that, in the past few days, we’ve seen an increase in attempts to exploit the vulnerability. We firmly believe that releasing the update out of band is the best thing to do to help protect our customers.”

The problem lies in the way Windows handles some .LNK shortcuts, particularly for icons on the desktop: the Windows Shell is not properly validating .LNK files in all cases.

Microsoft has been struggling with the security community in recent months, as an increasingly number of serious vulnerabilities have been revealed with giving Microsoft much advance warning; earlier this month, a group of security researchers actually vowed to look for Windows exploits and take them public without first sharing them with Microsoft at all. Microsoft has since extended an olive branch, announcing last week a new “coordinated vulnerability disclosure” process it hopes will address dissatisfaction in the broader security community.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Apple’s security trumps Microsoft and Twitter’s, say feds
Apple's Craig Federighi speaking about macOS security at WWDC 2022.

Apple has long held a reputation for rock-solid security, and now the U.S. government seemingly agrees after praising the company for its security procedures. At the same time, the feds have suggested Microsoft and Twitter need to pull their socks up and make their products much more secure for their users, according to CNBC.

In a speech given at Carnegie Mellon University, Cybersecurity and Infrastructure Security Agency Director Jen Easterly pointed to Apple as a company that took security and accountability seriously, and suggested other companies should take note.

Read more
Microsoft warns that relying on Internet Explorer may cause disruptions
windows 10 june update will kill internet explorer for good poznan  pol may 1 2021 laptop computer displaying logo

Microsoft has announced it will continue end-of-life updates in 2023 for its former browser, Internet Explorer, for older Windows versions.

Despite having ceased IE support on the current Windows 11 operating system version on June 15, Microsoft still allowed the legacy browser to function on many older versions, including Windows 10 Home, Pro, Enterprise, Edu, and IoT.

Read more
It’s not just you: Microsoft confirms Windows 11 is having gaming issues
Acer Predator Orion 7000 sitting on a table.

Microsoft has confirmed that the latest update to Windows 11 is causing performance issues in some games, along with a host of other problems. Stuttering might be noticeable in some apps as well.

Microsoft has put a hold on its Windows 11 22H2 update on devices affected by this issue; however, it is still possible to install the update manually. If you haven’t updated yet, it’s best to wait until you get a notification that an update is available.

Read more