Exploited Known exploited (KEV) CVE-2010-2568

Windows shortcut parsing flaw (CVE-2010-2568) — not opened, merely displayed, and it runs

Microsoft Windows Added to KEV Sep 15, 2022 Federal remediation due 2022-10-06

Shortcut files are parsed incorrectly, so code can run at the moment the icon is drawn on screen. What sets this apart is that it needs no action from the user, and it reached the catalog twelve years after the identifier was issued.

Key facts

  • CVE IDCVE-2010-2568
  • Affected (vendor / product)Microsoft Windows
  • CWECWE-20
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2022-10-06 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Shortcut parsing is incorrect, so code may run when the icon of a malicious shortcut is displayed (CWE-20).
  • A successful attacker is described as running code with the rights of whoever is signed in.
  • No opening or clicking is needed, so advice about not opening files has nothing to attach to.
  • Numbered in 2010 and listed on 15 September 2022, an interval of twelve years.
  • Of the 1,694 records this site holds as of 2026-09-04, 96 (5.7%) show an interval of ten years or more, including Microsoft 34, Adobe 25 and Oracle 9.

1Nothing was opened, and it ran

Most attacks need the user to do something: open the attachment, click the link, approve the prompt. What is unusual here is that no such move is required. To draw its icon, a shortcut file has to read information about what it points to. As the catalog describes it, that parsing is wrong, and code can run at the moment the icon is displayed. Open a folder, see its contents listed, and the condition is met.

The aspectAn attack needing a user actionAn attack that completes on display
The triggerOpening, clicking, approvingThe icon being drawn
Where training helpsUsers can be urged not to open things carelesslyAdvice about not opening has nothing to attach to
Where defense sitsPart of it can rest on user judgmentOnly the vendor fix remains

Telling people to be careful does not work here. Even the most careful person still looks at a folder listing. Where judgment cannot be relied on, applying the fix becomes the entire line of defense.

2What a twelve-year interval means

Interval for this entry12 yearsNumbered in 2010, listed 15 September 2022
Entries with an interval of ten years or more among the 1,694 this site holds as of 2026-09-04965.7% of the total
Vendors within those 96Microsoft 34, Adobe 25, Oracle 9Widely deployed platforms keep old entries alive

Ninety-six records show an interval of ten years or more, and more than a third of them name the same manufacturer. The more widely a platform was deployed, the longer its old versions survive. As long as they survive, so do the flaws in them. A catalog listing is confirmation that an old version is still running somewhere, and still being targeted.

3The reasons old things persist are not technical

Old versions persist mostly for reasons outside technology: work that cannot stop, tested combinations that cannot be disturbed, and a shortage of hands or budget for updating. So the presumption that something old is no longer dangerous does not hold. If anything, what is old and still running usually sits where updates reach least easily. That is what twelve years means.

Why it matters

A vulnerability that needs no user action puts awareness campaigns out of reach. Risks that training can reduce and risks that only a vendor fix can reduce deserve to be handled separately. Old versions also persist for operational rather than technical reasons, so the places updates reach least easily are exactly where old vulnerabilities survive longest.

FAQ

Is it dangerous even without opening the file?
The catalog states code may run when the icon of a malicious shortcut is displayed. No opening action is described as necessary.
Why was it listed twelve years later?
The catalog records what has been confirmed as exploited, so the listing reads as confirmation that old versions are still running and still targeted.
Are older vulnerabilities less dangerous?
No. Intervals of ten years or more account for 5.7% of entries, and the median allowance is 21 days at every interval.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#Security#Windows#Older vulnerabilities
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.