CVE-2026-25185General(microsoft / windows_10_1607)

MEDIUMCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • General: 5 classified signals
  • Disclosure: 4 classified signals
  • Peaked 5d ago at 4 mentions (2026-03-12); latest day: 2
  • 14 total mentions across 7 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline14 mentions / 7d
01234Mentions · 2026-03-11: 1Mentions · 2026-03-12: 4Mentions · 2026-03-13: 2Mentions · 2026-03-16: 3Mentions · 2026-03-23: 1Mentions · 2026-05-11: 1Mentions · 2026-05-25: 2PoC Mentioned / Linked · 2026-03-12: 1PoC Mentioned / Linked · 2026-03-23: 1Exploit Tool / Code · 2026-03-12: 1Exploit Tool / Code · 2026-03-23: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-05-25: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 3Technical Details · 2026-03-23: 1Technical Details · 2026-05-25: 103-1103-1203-1303-1603-2305-1105-25
Signal classification4 categories
General
535.7%
Disclosure
428.6%
Patch
321.4%
PoC
214.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-124
General2Patch1PoC1
2026-03-132
Disclosure1General1
2026-03-163
Disclosure2General1
2026-03-231
PoC1
2026-05-111
General1
2026-05-252
Patch2
Full discourse14 posts
  • TrustedSec@TrustedSec
    Patch

    Who knew a #Windows shortcut could carry so much? In our new blog, @freefirex2 breaks down the newly patched CVE-2026-25185 and how a specific #ExtraData block combination silently coerces authentication without a single click. Read it now! https://hubs.la/Q046xPgJ0

    Post summary

    The blog discusses the newly patched Windows shortcut vulnerability CVE-2026-25185, describing how a particular ExtraData block can silently bypass authentication—no PoC, exploit, or active exploitation is mentioned.

    1232422211.7K
    77.7K followersView on X
  • freefirex@freefirex2
    Disclosure

    I caught my first CVE :D https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-25185 Blog post inbound at http://TrustedSec.com tomorrow!

    Post summary

    The text announces the discoverer’s first CVE (CVE‑2026‑25185) and links to Microsoft’s update guide, but provides no exploit details, patches, or technical specifics.

    49066105.5K
    1.7K followersView on X
  • 0patch@0patch
    Patch

    Micropatches released for Windows Shell Link Processing Spoofing Vulnerability (CVE-2026-25185) https://blog.0patch.com/2026/05/micropatches-released-for-windows-shell.html https://t.co/D3GYGgMkYT

    Post summary

    Micropatches have been released to mitigate the Windows Shell Link Processing Spoofing vulnerability CVE‑2026‑25185, as announced by 0patch.

    19036194.0K
    8.4K followersView on X
  • Florian Hansemann@CyberWarship
    General

    ''LnkMeMaybe - A Review of CVE-2026-25185'' #infosec #pentest #redteam #blueteam https://trustedsec.com/blog/lnkmemaybe-a-review-of-cve-2026-25185

    Post summary

    The post is a brief mention of a blog review on CVE‑2026‑25185, lacking specific evidence of PoC, exploit availability, active use, patches, or technical details.

    0105131.6K
    88.5K followersView on X
  • Mr.Rabbit@01ra66it
    PoC

    このWindows .lnk脆弱性は、細工したショートカットを置くだけで、被害端末が攻撃者側へ自動認証し、ネットワーク情報や認証情報を漏らし得る点が重要。PoCはすでに公開されており、研究者はこれを “LnkMeMaybe” として解説している。 CVEは CVE-2026-25185。NVDは Windows Shell Link Processing の情報漏えい/ネットワーク越しの spoofing と説明しており、CVSS v3.1 は 5.8、ベクトルは AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N。TrustedSecによると、Darwin ExtraData block と Icon Environment block を組み合わせた .lnk で、ユーザーが開かなくてもフォルダ表示時の処理だけで外部パス参照が走り、認証が飛ぶ。さらに Windows Search indexing service と Windows Defender でも同じ読み込み経路が使われるとしている。 APT: なし Malware: なし CVE: CVE-2026-25185 IoC: .lnk, Darwin ExtraData block, Icon Environment block, Windows Shell Link Processing, external SMB/UNC path, LnkMeMaybe #CyberSecurity #ThreatIntel #Windows #LNK #CVE202625185 https://securityonline.info/poc-exploit-code-now-public-windows-lnk-shortcut-flaw-leaks-sensitive-network-data/

    Post summary

    The post announces the Windows .lnk vulnerability CVE‑2026‑25185, details how it leaks credentials via SMB/UNC paths, and confirms a published PoC named LnkMeMaybe along with technical specifics.

    00041373
    3.4K followersView on X
  • ET Labs@ET_Labs
    General

    51 new OPEN, 137 new PRO (51 + 86) DoHDoor, LandUpdate808, LOTUSLITE, Malformed ZIP headers (Zombie ZIP) File Inbound, NetSupport RAT, TA2726, TA4903, TA569, UNK_NightOwl, Lumma Stealer, XWorm, Windows Shell Link Processing Spoofing (CVE-2026-25185) https://community.emergingthreats.net/t/ruleset-update-summary-2026-03-16-v11149/3234 https://t.co/BxqtFDyagW

    Post summary

    The update lists several new malware campaigns and one specific vulnerability (CVE‑2026‑25185) related to Windows Shell Link spoofing, but offers no PoC, exploit code, active use, or patch details.

    02030330
    5.7K followersView on X
  • Brian Halbach ☕️@brianhalbach
    PoC

    @TrustedSec putting out great content and tools as always. I can't wait to play around with this. https://github.com/trustedsec/LnkMeMaybe https://trustedsec.com/blog/lnkmemaybe-a-review-of-cve-2026-25185

    Post summary

    The tweet shares a GitHub repo and blog post for CVE‑2026‑25185, indicating a proof‑of‑concept or tool exists, but there is no evidence of active exploitation or patch information.

    0003066
    1.3K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20127 2 - CVE-2023-43010 3 - CVE-2026-21385 4 - CVE-2025-68613 5 - CVE-2026-25185 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVEs without providing any additional context, details, or actionable information.

    00010243
    1.7K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @TrustedSec @freefirex2 Zero-click auth coercion through Windows shortcuts is terrifying! CVE-2026-25185 shows how ExtraData blocks can silently force authentication without any user interaction. https://vulntracker.io/cves/CVE-2026-25185

    Post summary

    The tweet announces that CVE-2026-25185 enables zero‑click authentication coercion via Windows shortcuts using ExtraData blocks, highlighting a serious vulnerability but providing no PoC, exploit code, patch, or evidence of active exploitation.

    00010199
    415 followersView on X
  • Israel@f1tym1
    Patch

    Micropatches released for Windows Shell Link Processing Spoofing Vulnerability (CVE-2026-25185) https://ift.tt/ThfXKea March 2026 Windows Updates brought a patch for CVE-2026-25185, Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get …

    Post summary

    Micropatches addressing CVE-2026-25185 were released in March 2026 as part of Windows updates, fixing a shell link spoofing vulnerability.

    0000045
    980 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25185 Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network. https://www.cve.org/CVERecord?id=CVE-2026-25185 ----- Traducción: CVE-2026-25185 Exposición d… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-25185, describing a Windows Shell Link Processing flaw that can expose sensitive data and enable spoofing, with no evidence of exploits, patches, or active attacks.

    0000037
    58 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25185 Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network. https://www.cve.org/CVERecord?id=CVE-2026-25185

    Post summary

    A new vulnerability, CVE-2026-25185, is highlighted, detailing sensitive data exposure in Windows Shell Link that could be abused for spoofing, but no PoC, exploitation, or patch information is provided.

    00000228
    56.7K followersView on X
  • X CyberSec@xcybersecnews
    General

    🚨 Unpack the mysteries of CVE-2026-25185! Our "LnkMeMaybe" review breaks down this critical vulnerability, offering insights you need to stay secure. #CVE #Cybersecurity https://trustedsec.com/blog/lnkmemaybe-a-review-of-cve-2026-25185

    Post summary

    The tweet promotes a blog review of CVE‑2026‑25185 but offers no PoC, exploit, patch, or technical specifics.

    0000030
    163 followersView on X
  • Cyber Research@Cyb3rR3s34rch
    General

    Originally from TrustedSec: LnkMeMaybe - A Review of CVE-2026-25185 https://trustedsec.com/blog/lnkmemaybe-a-review-of-cve-2026-25185 ( :-{ı▓ #trustedsec #pentesting #cyberresearch https://t.co/a2DbwckZAK

    Post summary

    The tweet merely references a blog post that reviews CVE-2026-25185, offering no further technical or operational details.

    0000031
    54 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more