AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-9491

HIGH · CVSS 7.8 EPSS 68.86% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-08-26 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. It affects Microsoft, Windows. Public exploit code or proof-of-concept references have been detected in its references. Its EPSS score suggests a 68.9% probability of exploitation in the next 30 days. It may be remotely exploitable.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-9491
Severity
HIGH
CVSS
7.8
EPSS
68.86%
Microsoft Windows

Original NVD Description

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of .LNK files. Crafted data in an .LNK file can cause hazardous content in the file to be invisible to a user who inspects the file via the Windows-provided user interface. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25373.

Related CVEs

Other vulnerabilities affecting the same vendor(s)