← back
CVE-2025-33053

Internet Shortcut Files Remote Code Execution Vulnerability

CVSS 8.8 HIGHEPSS 81.6%● KEVCWE-73
In short

Windows Internet Shortcut files (.url) can be manipulated to execute malicious code when opened, allowing attackers to take over a computer remotely without special access.

Technical detail

CWE-73 (External Control of File Name or Path) in Internet Shortcut file handling permits remote code execution via crafted .url files. The vulnerability requires user interaction (file opening) and network access, but bypasses standard execution protections to achieve arbitrary code execution with user privileges.

Summary generated and translated by AI from the official description.
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →