CVE-2017-8464General(microsoft / windows_10_1511)

LOWCVSS 8.8 · HIGHCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka "LNK Remote Code Execution Vulnerability."

2.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-08-10. Apply updates per vendor instructions.

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1511
  • windows_10_1607
  • windows_10_1703
  • windows_7

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1511windows_10_1607windows_10_1703windows_7windows_8.1windows_rt_8.1windows_server_2008windows_server_2012windows_server_2016

2 versions affected across 9 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-16: 1Mentions · 2026-08-11: 1PoC Mentioned / Linked · 2026-08-11: 1Technical Details · 2026-08-11: 102-1608-11
Signal classification2 categories
General
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-161
General1
2026-08-111
PoC1
Full discourse2 posts
  • ܛܔܔܔܛܔܛܔܛ@skocherhan
    General

    fe2bc6b60f9a1b846a8214adf9f2c33e 2 detections @nextronresearch CVE-2010-2568 & CVE-2017-8464 #PlugX https://t.co/6QiFem8jkQ

    Post summary

    The text references two CVEs and notes two detections of PlugX malware, but does not provide detailed technical, exploit, or mitigation information.

    00061294
    26.3K followersView on X
  • Eric Taylor@bcs_erictaylor
    PoC

    Can we just get these CVE's to chill out.. Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives. https://epsslookuptool.com/?cve=CVE-2017-8464 POC: https://github.com/PlayBoiSK8/POC-CVE-2017-8464-OpenCalculator/tree/main

    Post summary

    A GitHub repository providing a proof‑of‑concept for CVE‑2017‑8464 is linked, and the post briefly describes the .lnk vulnerability with explorer.exe and USB drives, but no patches or active exploitation are mentioned.

    00010103
    692 followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1511---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1703---
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-itanium
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---

Explore more