RULE(RULE ID:320440)

Rule General Information
Release Date: 2021-06-15
Rule Name: Microsoft Windows LNK Remote Code Execution Vulnerability (CVE-2017-8464)
Severity:
CVE ID:
Rule Protection Details
Description: Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka;LNK Remote Code Execution Vulnerability.;
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows
Reference: SecurityFocusBID:98818
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8464
ExploitDB:42429
SecurityTrackerID:1038671
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8464