CVE Tools

Description

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka "LNK Remote Code Execution Vulnerability."

In plain language

AI Act now

This is a knownly exploited flaw in older Microsoft Windows versions that can let a booby-trapped shortcut take over a computer, so affected systems need Microsoft’s security updates.

Executive summary

CVE-2017-8464 is a Windows Shell remote code execution vulnerability in which parsing a crafted .LNK shortcut icon can execute attacker-controlled code.

If affected, business impact
Full computer takeoverCustomer data exposureRansomware riskBusiness interruption

What to do now

  1. Check whether any computers or servers run the affected older Microsoft Windows versions and whether the security update for CVE-2017-8464 is installed.
  2. Install the Microsoft security update for your exact Windows release using Microsoft’s advisory; the supplied findings do not identify one universal fixed version number.
  3. Until every affected device is updated, block or quarantine shortcut files from email, downloads, shared drives, and removable media.
  4. Ask IT to investigate any unexpected shortcut files or unusual activity on affected machines.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:RS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 10 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Feb 10, 2022
Remediation due:Aug 10, 2022

Required action: Apply updates per vendor instructions.

2 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 3 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2017-8464 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store