Microsoft disclosed CVE-2025-33053, an Important remote code execution flaw in Internet Shortcut Files that affects all supported versions of Windows and carries a CVSS 8.8 rating. The vulnerability is tied to CWE-73 (external control of file name or path) and can let an unauthenticated attacker execute code over a network if a user clicks a specially crafted URL. Microsoft said the bug had been exploited in the wild, that functional exploit code was available, and that security updates had been released.
The advisory said the issue has implications beyond legacy browser use because underlying MSHTML, EdgeHTML, and scripting components remain supported on some platforms and are still used by Internet Explorer mode, the WebBrowser control, WebView, and some UWP applications. Microsoft also noted that IE cumulative updates still matter for certain older Windows Server systems, and later revised the advisory to correct the CVE title and description without changing the technical impact. Related Microsoft advisories show the flaw joins a broader pattern of remote code execution risks across Windows and server products, including MSHTML, Hyper-V, Exchange Server, and SharePoint Server.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft updated the CVE-2025-33053 advisory to correct the CVE title and description. The company noted the June 19 change was informational only.
Microsoft published advisory CVE-2025-33053 for an Internet Shortcut Files remote code execution vulnerability affecting supported Windows versions. The company said the flaw was being exploited in the wild, functional exploit code was available, and an official fix was released.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.