A non-nul-day error has been exploited by 11 nation-state attacks


  • Trend Micro warns of an old Windows zero-day still in use today
  • Many national states abuse the mistake of running espionage campaigns
  • Microsoft does not find it critical

A Windows zero-day vulnerability that has been unmatched for eight years has been exploited by 11 nation-state attacks and countless financially motivated groups, experts have warned.

Trend Micros Zero Day Initiative (ZDI) criticized Microsoft for taking down the importance of the results in the vulnerability, the track like ZDI-CAN-25373, which is a mistake in Windows that allows attackers to prepare malicious shortcut (.lnk) files that enable the execution of hidden commands when a user interacts with these files.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top