CVE-2010-2568General(microsoft / windows_7)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_7 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-10-06. Apply updates per vendor instructions.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_7
  • windows_server_2003
  • windows_server_2008
  • windows_vista

Threat summary

  • Active exploitation appears in 2 classified signals
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-22); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
windows_7windows_server_2003windows_server_2008windows_vistawindows_xp

2 versions affected across 5 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-16: 1Mentions · 2026-03-02: 1Mentions · 2026-06-22: 2Mentions · 2026-06-27: 1Active Exploitation · 2026-03-02: 1Active Exploitation · 2026-06-22: 1Technical Details · 2026-06-22: 102-1603-0206-2206-27
Signal classification2 categories
General
360.0%
Active Exploitation
240.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-161
General1
2026-03-021
Active Exploitation1
2026-06-222
Active Exploitation1General1
2026-06-271
General1
Full discourse5 posts
  • OS Dev@OSdev_
    Active Exploitation

    CVE-2010-2568 (Stuxnet LNK Vulnerability) the most technically sophisticated Windows vulnerability. Stuxnet abused a flaw in how Windows Explorer rendered shortcut (.LNK) icons. Simply viewing a folder containing a malicious shortcut could execute code. The vulnerability itself was impressive, but what made it legendary was how it was combined with multiple other Windows zero-days and stolen certificates to attack Iranian nuclear facilities. Stuxnet used four Windows zero-days simultaneously, something almost unheard of at the time. Why Windows engineers should study it ? - Multiple chained exploits - Kernel-level rootkits - PLC/industrial control manipulation - Nation-state engineering effort Years of stealth operation

    Post summary

    The post describes Stuxnet’s exploitation of CVE‑2010‑2568 via a malicious .LNK file that triggers code execution in Windows Explorer, detailing how the vulnerability was used in real‑world attacks against Iranian nuclear facilities, but it offers no PoC or patch information.

    291855317.1K
    4.8K followersView on X
  • msuiche@msuiche
    General

    True. Here is an analysis done by GLM 5.2 model of the LNK vulnerability. cc @OSdev_ https://www.msuiche.com/posts/cve-2010-2568-stuxnet-lnk/

    Post summary

    The post includes a link to an analysis of CVE-2010-2568 but offers no further technical details or evidence of exploitation.

    2001152.4K
    1.9K followersView on X
  • OS Dev@OSdev_
    General

    https://medium.com/@zhoukeye11/cve-2010-2568-vulnerability-b229c511083a

    Post summary

    The text merely references a Medium article about CVE‑2010‑2568 without providing additional details or context.

    010741.6K
    4.8K followersView on X
  • ܛܔܔܔܛܔܛܔܛ@skocherhan
    General

    fe2bc6b60f9a1b846a8214adf9f2c33e 2 detections @nextronresearch CVE-2010-2568 & CVE-2017-8464 #PlugX https://t.co/6QiFem8jkQ

    Post summary

    The tweet references two CVEs and a PlugX link but provides no PoC, exploitation details, patches, or technical specifics.

    00061294
    26.3K followersView on X
  • David@davidsheyi
    Active Exploitation

    2/ Stuxnet (CVE-2010-2568) is a classic example. It leveraged multiple zero-days to disrupt Iranian nuclear centrifuges, showcasing the potential scale of damage. #CVE #InfoSec

    Post summary

    The post references Stuxnet’s use of CVE‑2010‑2568 to exploit zero‑days and disrupt Iranian nuclear centrifuges, illustrating real‑world exploitation.

    1000037
    557 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_7---
OSmicrosoftwindows_server_2003---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-itanium
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_vista---
OSmicrosoftwindows_vista---
OSmicrosoftwindows_xp--x64
OSmicrosoftwindows_xp---

Explore more