#VU20271 Input validation error in Windows and Windows Server - CVE-2019-1188
Published: August 14, 2019
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input when processing .LNK files. A remote attacker can trick the victim to open a drive or remote share with malicious Windows shortcut file (.LNK) with Windows Explorer and execute arbitrary code on the system with privileges of the current user.