The zero-day LNK (shortcut) Windows vulnerability that Aleks blogged about last week has been classified as CVE-2010-2568 and is being actively exploited in the wild. There doesnt seem to be any security model associated with how Windows handles shortcuts. Microsoft has released generic detection for malicious LNK files which try to exploit the feature. I think that the LNK format will start receiving a lot more attention now, both from the good guys, and the bad, so take a look at the mitigations put up by Microsoft.”]
Source: https://securelist.com/lnk-zero-day-the-fundamentals/29617/

