There are two main security flaws in Windows that are currently in use

A bug in the Windows Shortcuts Binary Format and another bug in Windows Server are two big headaches for Microsoft that have yet to be resolved, unfortunately these are bugs that are being used on a large scale

There are two main security flaws in Windows that are currently in use
Microsoft is unable to patch two vulnerabilities in Windows, one of which dates back to 2017

Windows has a huge security problem, specifically two vulnerabilities that have not been fully patched. One of them is a type of “zero day” that has been in use since 2017, in addition to a critical flaw that has been unsuccessfully tried to fix. Attacks have increased across much of the Internet. Which Ars Technica reports that it does a massive coordinated operation that seems to have no end in sight. Windows 11 found one that dates back to 2023 and took a year to resolve, and another that allowed the system to be installed on incompatible computers.

Two incredible security-breaking bugs in Windows, one from 2017, haven’t been fixed

The zero-day vulnerability was only discovered last March. Security company Trend Micro discovered that it has been used by various threat groups since 2017. Some of them are associated with the nation-states of the world. The vulnerability, identified as “ZDI-CAN-25373”, installs infrastructure payloads in more than 60 countries. We are at the end of the year and Microsoft has not been able to deal with this failure. Its origin lies in the village Windows shortcuts binary format. What causes this speeds up opening programs or accessing files triggered by said binary without having to locate it.

One of its variants, linked to a Chinese group, exploits a vulnerability against European countries; remote access trojan named “PlugX”. The vulnerability is disguised as an RC4 format to advance its target and evolve. Although there is no specific patch for this type of vulnerability, Users can protect themselves by limiting the functionality of .ink files if they are blocked or restricted for use from untrusted sources. This is possible by configuring Windows Explorer.

Windows vulnerabilities

Microsoft is actively working to find solutions against computer attacks

The second bug is related to remote code execution in Windows Server Update Services. It was distributed by a “computer worm” caused by a serialization failure. Apparently this was already fixed with an unscheduled update, but it was later revealed that the fix was not complete. It was used again, the security company reported that the vulnerability was discovered. The bug was named “CVE-2025-59287”. The targets are WSUS servers that are present on the Internet. The most current bug, renamed “CVE-2025-9491” (from day zero), still doesn’t have an exact fix date.

Leave a Reply

Your email address will not be published. Required fields are marked *