Tech

An unpatched Windows zero-day flaw has been exploited by 11 nation-state attackers

Share
Share


  • Trend Micro warns of an old Windows zero-day still in use today
  • Many nation-states are abusing the bug to run espionage campaigns
  • Microsoft doesn’t deem it critical

A Windows zero-day vulnerability which has remained unpatched for eight years has been exploited by 11 nation-state attackers, and countless financially motivated groups, experts have warned.

Trend Micro’s Zero Day Initiative (ZDI) criticized Microsoft for downplaying the importance of the findings into the vulnerability, tracked as ZDI-CAN-25373, which is a flaw in Windows that allows attackers to craft malicious shortcut (.lnk) files, enabling the execution of hidden commands when a user interacts with these files.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *