Windows shortcut parsing flaw (CVE-2010-2568) — not opened, merely displayed, and it runs
Shortcut files are parsed incorrectly, so code can run at the moment the icon is drawn on screen. What sets this apart is that it needs no action from the user, and it reached the catalog twelve years after the identifier was issued.
Key facts
- CVE IDCVE-2010-2568
- Affected (vendor / product)Microsoft Windows
- CWECWE-20
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2022-10-06 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Shortcut parsing is incorrect, so code may run when the icon of a malicious shortcut is displayed (CWE-20).
- A successful attacker is described as running code with the rights of whoever is signed in.
- No opening or clicking is needed, so advice about not opening files has nothing to attach to.
- Numbered in 2010 and listed on 15 September 2022, an interval of twelve years.
- Of the 1,694 records this site holds as of 2026-09-04, 96 (5.7%) show an interval of ten years or more, including Microsoft 34, Adobe 25 and Oracle 9.
1Nothing was opened, and it ran
Most attacks need the user to do something: open the attachment, click the link, approve the prompt. What is unusual here is that no such move is required. To draw its icon, a shortcut file has to read information about what it points to. As the catalog describes it, that parsing is wrong, and code can run at the moment the icon is displayed. Open a folder, see its contents listed, and the condition is met.
Telling people to be careful does not work here. Even the most careful person still looks at a folder listing. Where judgment cannot be relied on, applying the fix becomes the entire line of defense.
2What a twelve-year interval means
Ninety-six records show an interval of ten years or more, and more than a third of them name the same manufacturer. The more widely a platform was deployed, the longer its old versions survive. As long as they survive, so do the flaws in them. A catalog listing is confirmation that an old version is still running somewhere, and still being targeted.
3The reasons old things persist are not technical
Old versions persist mostly for reasons outside technology: work that cannot stop, tested combinations that cannot be disturbed, and a shortage of hands or budget for updating. So the presumption that something old is no longer dangerous does not hold. If anything, what is old and still running usually sits where updates reach least easily. That is what twelve years means.
Why it matters
A vulnerability that needs no user action puts awareness campaigns out of reach. Risks that training can reduce and risks that only a vendor fix can reduce deserve to be handled separately. Old versions also persist for operational rather than technical reasons, so the places updates reach least easily are exactly where old vulnerabilities survive longest.
FAQ
Is it dangerous even without opening the file?
Why was it listed twelve years later?
Are older vulnerabilities less dangerous?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).