CVE-2025-9491Active Exploitation(microsoft / windows_11_23h2)

HIGHCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows_11_23h2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of .LNK files. Crafted data in an .LNK file can cause hazardous content in the file to be invisible to a user who inspects the file via the Windows-provided user interface. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25373.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-451

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_23h2

Threat summary

  • Active exploitation appears in 4 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 2 mentions (2026-07-03); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
windows_11_23h2

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-13: 1Mentions · 2026-07-03: 2Mentions · 2026-07-15: 1Exploit Tool / Code · 2026-07-03: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-07-03: 2Active Exploitation · 2026-07-15: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-04-13: 104-1307-0307-15
Signal classification1 categories
Active Exploitation
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-131
Active Exploitation1
2026-07-032
Active Exploitation2
2026-07-151
Active Exploitation1
Full discourse4 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ Armored Likho targeted power and government agencies. Kaspersky says the attacks span Russia, Brazil, and Kazakhstan, using BusySnake Stealer, GitHub-hosted payloads, Go2Tunnel reverse tunneling, and patched CVE-2025-9491 LNK abuse. How the stealer chain works: https://thehackernews.com/2026/07/armored-likho-targets-government.html

    Post summary

    The text reports that Armored Likho actors are actively exploiting CVE-2025-9491 via LNK abuse across multiple countries, with the vulnerability already patched by vendors.

    09048820.1K
    2.3M followersView on X
  • ThreatFoXX@Dixit_404
    Active Exploitation

    @smica83 @skocherhan @malwrhunterteam @ElementalX2 Exploiting CVE-2025-9491 of LNK

    Post summary

    The message indicates that CVE-2025-9491 related to LNK is being actively exploited, but it provides no technical details, PoC, or mitigation information.

    02020599
    443 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2025-9491 Exploit in the wild confirmed for CVE-2025-9491 (CVSS null). Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The tweet announces confirmed in‑the‑wild exploitation of CVE‑2025‑9491, a Windows LNK RMCE vulnerability, with no patch or workaround mentioned.

    00020209
    5.6K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows Armored Likho exploiting CVE-2025-9491 to deploy BusySnake Stealer across government and energy sectors. Attackers established SSH tunnels for C2 and exfiltrated browser cookies, credentials, and crypto wallets. Runtime segmentation helps contain post-compromise lateral movement in these multi-stage campaigns. #ThreatIntel #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/armored-likho-busysnake-stealer-2026

    Post summary

    TRC analysis reports that CVE-2025-9491 is actively exploited by Armored Likho, deploying the BusySnake Stealer with SSH‑tunneled C2 to exfiltrate browser data and crypto wallets across government and energy sectors.

    0000045
    1.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_23h210.0.22631.4169-x64

Explore more