Microsoft has silently plugged a security flaw that has been
exploited by several threat actors since 2017 as part of the
company's November 2025 Patch Tuesday updates, according to ACROS
Security's 0patch. The vulnerability in question is CVE-2025-9491
(CVSS score: 7.8/7.0), which has been described as a Windows
Shortcut (LNK) file UI misinterpretation vulnerability that could
lead to remote
Read more https://thehackernews.com/2025/12/microsoft-silently-patches-windows-lnk.html

