Microsoft Windows LNK Shortcut Automatic DLL Loading Exploit (MS15-020)

Microsoft Windows is prone to a vulnerability that may allow a DLL file to be automatically loaded because the software fails to handle LNK files properly. Specifically, the issue occurs when loading the icon of a shortcut file. A specially crafted LNK file can cause Windows to automatically execute code that is specified by the shortcut file. The attacker must entice a victim into viewing a specially crafted shortcut. The shortcut file and the associated binary may be delivered to a user through removable drives. An attacker may exploit this issue to execute arbitrary code. This vulnerability is the result of an incomplete fix for MS10-046 (CVE-2010-2568).
Exploit Platform
Exploit Type
Product Name