Windows快捷方式漏洞(亦称lnk漏洞)是2010年7月份发现的一个高危漏洞,几乎所有的Windows系统都受到此漏洞的影响。本文详细分析了Windows操作系统解析lnk文件的过程,并结合逆向工程技术剖析了lnk漏洞的工作原理。在此基础上,设计实现了一个lnk漏洞例程,并提交VirusTotal网站检测,结果说明目前lnk漏洞仍然存在安全威胁。
Microsoft Windows Shortcut Vulnerability also known as 'lnk' files automatic execution vulnerability is a high-risk vulnerability announced in July 2010.Almost all windows Operating Systems are affected by this vulnerability.In this paper we describe how the lnk files work and the principle of the vulnerability combined with reverse analysis technology.Then we designed a simple test procedure and send the malicious lnk file to the free virus check Website,VirusTotal.com.The results show that the vulnerability is still a hazard.