HTTP: .LNK File Download

This signature detects a HTTP request for the download of a file with the .lnk extension. Such a file could be maliciously crafted to execute arbitrary code or trick the user into executing another program unintentionally.

Extended Description

Microsoft Windows is prone to a vulnerability that may allow a file to automatically run because the software fails to properly handle 'LNK' files or 'PIF' files. An attacker may exploit this issue to execute arbitrary code. The attacker must entice a victim to view a specially crafted shortcut. NOTE: This issue is being exploited in the wild with W32.Stuxnet (previously known as W32.Temphid). This issue affects Microsoft Windows XP, Windows Vista, Windows 7, Windows Server 2003, and Windows Server 2008.

Affected Products

Avaya messaging_application_server,Microsoft windows_server_2008_for_itanium-based_systems

Short Name
HTTP:EXT:DOT-LNK
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
.LNK CVE-2005-2118 CVE-2010-2568 Download File bid:15070 bid:41732
Release Date
10/11/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Microsoft

Avaya

CVSS Score

9.3

5.1

Found a potential security threat?