Microsoft Warns of .LNK Flaw

SUNNYVALE, Calif. — Microsoft has issued an advisory for the vulnerability affecting all current versions of Windows, including the recently released service pack one of Windows 7 and Windows server 2008 R2.

PCMag reports the bug comes from Windows improperly handling shortcut (.LNK) files executed through the shell, typically Windows Explorer.

When the user launches such a shortcut through the associated icon, Windows fails to properly validate the parameters of the shortcut and malicious code in the .LNK may be executed.

The attack would typically be performed through removable drives, like USB thumb drives of CD-ROMs.

Microsoft lists two workarounds in the advisory. The first disables the display of icons for shortcuts, which will create a very wrong-looking situation in Windows Explorer. The second disables the WebDAV client service, which only affects that vector.

Microsoft has begun their process of investigation and patch development and this is the sort of attack that can be found and blocked by conventional anti-malware.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Rachel Steele Curates FapHouse's 'Creator's Choice' Project

Fan platform FapHouse has selected content creator Rachel Steele to curate its first Creator's Choice project.

FSC Sues Tennessee Over AV Law, Seeks Preliminary Injunction

Free Speech Coalition, along with a group of adult industry stakeholders, has filed a legal challenge to Tennessee’s age verification law and requested an expedited preliminary injunction against enforcement.

Former Backpage Owner Michael Lacey Released on Bail From Federal Prison

Backpage.com co-founder Michael Lacey has been released from federal prison on $1 million bail, pending the appeal of his conviction for money laundering.

Indiana, Ohio AGs File Amicus Brief in Support of Texas AV Law

Indiana Attorney General Todd Rokita, along with Ohio Attorney General Dave Yost and officials from 22 other states, on Friday filed an amicus brief with the United States Supreme Court in support of Texas’ controversial age verification law.

Corey Silverstein's 'New US President' Webinar Now Streaming

Adult industry attorney Corey D. Silverstein's latest "Legal Impact" webinar, titled "We Have a New US President: Legal and Community Implications," is now available for streaming.

Lisa Ann Guests on Chaturbate's 'Sex Tales' Podcast

Lisa Ann is the latest guest on Chaturbate’s “Sex Tales” podcast, hosted by Melissa Stratton and Vanniall, and streaming on the company’s “Camming Life” YouTube channel.

Bluesky Verification Service 'BSky Verified' Launches

"And Now We Drink" podcast host Matt Slayer has launched BSky Verified, a third-party service that vets adult performers, content creators and other notable people and provides a customized domain for handles on the Bluesky social media platform.

Dirty Cinema Launches New Paysite 'MILFuckd'

Dirty Cinema has launched a new paysite, MILFuckd.com, on its network.

Braindance Unveils '6DOF' VR Tech

Interactive virtual reality platform Braindance has debuted its new Six Degrees of Freedom (6DOF) VR technology.

Kiiroo, Pineapple Support Launch 'Empower Hour' Series on FeelHubX YouTube Channel

Kiiroo and Pineapple Support have teamed up to launch the “Empower Hour” series on the FeelHubX YouTube channel.

Show More