CVE-2017-8464
Description
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka "LNK Remote Code Execution Vulnerability."
In plain language
AI Act nowThis is a knownly exploited flaw in older Microsoft Windows versions that can let a booby-trapped shortcut take over a computer, so affected systems need Microsoft’s security updates.
CVE-2017-8464 is a Windows Shell remote code execution vulnerability in which parsing a crafted .LNK shortcut icon can execute attacker-controlled code.
What to do now
- Check whether any computers or servers run the affected older Microsoft Windows versions and whether the security update for CVE-2017-8464 is installed.
- Install the Microsoft security update for your exact Windows release using Microsoft’s advisory; the supplied findings do not identify one universal fixed version number.
- Until every affected device is updated, block or quarantine shortcut files from email, downloads, shared drives, and removable media.
- Ask IT to investigate any unexpected shortcut files or unusual activity on affected machines.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-8464 and every CVE in our database. Create a free account — no credit card required.
Create Free Account