A flaw tracked as CVE-2010-2568 allowed arbitrary code execution on multiple Microsoft Windows versions through crafted .LNK and .PIF shortcut files. The vulnerability stemmed from Windows Explorer improperly handling shortcut files while displaying their icons, meaning malicious code could be triggered simply when a user browsed to a location containing the weaponized shortcut. Affected systems included Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7.
The issue was observed in the wild and became closely associated with malware activity targeting industrial environments, including reporting tied to Siemens WinCC SCADA-related exploitation. Microsoft identified the issue in advisory 2286198 and addressed it in security update MS10-046, while US-CERT also highlighted the vulnerability as part of broader Microsoft security updates. The bug could be exploited by local users or remote attackers if a victim accessed removable media or network shares containing the malicious shortcut files.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2010-2568 was updated. The update date listed in the record is 2018-10-12.
CVE-2010-2568 was published as a Microsoft Windows Shell remote code execution vulnerability involving crafted .LNK or .PIF shortcut files. The record identifies affected Windows versions and links the issue to Microsoft advisory MS10-046.
The Windows Shell shortcut handling vulnerability later tracked as CVE-2010-2568 was demonstrated in the wild in July 2010. The CVE record says it was originally reported in connection with malware leveraging CVE-2010-2772 in Siemens WinCC SCADA systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.