Skip to main content

CVE detail

CVE-2010-2568

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.

CVSS 7.8 · HighBuzz score 69.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 69.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
23 evidence mentions in the snapshot
Diversity score
14.5
5 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
23 source links · newest first
  • Our telemetry shows a surge in Windows shortcut (LNK) malware use. We explain how attackers exploit LNK files for malware delivery.

    vendorunit42.paloaltonetworks.comJul 2, 2025, 10:00 AM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including the bug used in the Stuxnet attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six new vulnerabilities to its Known Exploited Vulnerabilities Catalog. Below is the list of vulnerabilities added to the catalog: CVE-2022-40139: Trend […]

    newssecurityaffairs.comSep 17, 2022, 3:11 PM
  • An analysis of 17 espionage frameworks designed to target air-gapped networks shows that all of them leverage USB drives and all target Windows exclusively, ESET reports.

    newswww.securityweek.comDec 3, 2021, 12:20 PM
  • Microsoft released a new security update on June 17th in an attempt to patch a vulnerability which allowed the Stuxnet Virus to exploit Windows systems. The Stuxnet Virus which attacks Industrial Control Systems was first discovered in 2010 when it infected Iranian Programmable Logic Controllers. Stuxnet compromises controllers by first targeting Windows operating systems and […]

    newssecurityaffairs.comAug 4, 2017, 6:22 PM
  • One of the patches released by Microsoft as part of its June 2017 security updates represents the company’s third attempt at patching an old vulnerability exploited by the notorious Stuxnet worm in 2010.

    newswww.securityweek.comAug 4, 2017, 12:39 PM
  • WikiLeaks published several documents on Thursday detailing a tool allegedly used by the U.S. Central Intelligence Agency (CIA) to hack air-gapped networks through USB drives.

    newswww.securityweek.comJun 23, 2017, 7:20 AM
  • A report published by Kaspersky Lab on Thursday shows that the number of attacks involving exploits increased significantly in 2016 compared to the previous year, but the number of attacked users actually dropped.

    newswww.securityweek.comApr 21, 2017, 1:47 PM
  • A new report published by Kaspersky confirms that Stuxnet exploits targeting a Windows Shell Vulnerability is still widely adopted by threat actors. The case that I’m going to present to you demonstrates the importance of patch management and shows the effects of the militarization of cyberspace. Unpatched software is an easy target for hackers that can exploit […]

    newssecurityaffairs.comApr 21, 2017, 1:10 PM
  • Attacks conducted with the help of exploits are among the most effective as they generally do not require any user interaction, and can deliver dangerous code without arousing user suspicion. According to data gathered by Kaspersky Lab, there were 702 million attempts to launch an exploit in 2016 – an increase of 24.54 percent from 2015. During the same period, more than 297,000 users worldwide were attacked by unknown exploits (zero-day and heavily obfuscated known … More →

    newswww.helpnetsecurity.comApr 21, 2017, 12:50 PM
  • Users that run unpatched software beware. Hackers have been relying on an old software bug tied to the Stuxnet worm to carry out their attacks. Microsoft may have initially patched the flaw in 2010, but it’s nevertheless become the most widespread software exploit, according to security firm Kaspersky Lab. On Thursday, Kaspersky posted research examining […]

    newswww.csoonline.comApr 20, 2017, 9:01 PM
  • Exploit kits are how most malware gets on victims’ computers and, according to Microsoft, encounters with exploit kits increased by more than a third from 3Q15 to 4Q15. The second place on the list of exploits most commonly detected and blocked by Microsoft real-time antimalware products in 2H15 is the one for CVE-2010-2568, the Windows Shell Shortcut Icon Loading Vulnerability which was one of the four flaws used by the attackers who released the Stuxnet … More →

    newswww.helpnetsecurity.comMay 9, 2016, 3:07 PM
  • The most commonly targeted vulnerability in 2015 was a Windows flaw that came to light in 2010 after being exploited by the notorious Stuxnet malware, Microsoft said in its latest Security Intelligence Report (SIR).

    newswww.securityweek.comMay 6, 2016, 3:50 PM
  • Security researchers have teamed up with the law enforcement community for another takedown of a malware network.

    newswww.securityweek.comApr 9, 2015, 5:00 PM
  • A security bulletin recently released by Microsoft addresses the LNK flaw that was exploited by Stuxnet and that we have wrongly considered patched since 2010. If you followed IT in the last few years, you might remember that Stuxnet was discovered around mid-2010 and at the time it was used against the Iranian nuclear program. […]

    newssecurityaffairs.comMar 13, 2015, 7:11 AM
  • One of the security bulletins released by Microsoft on Tuesday addresses a vulnerability that should have been patched since August 2010.

    newswww.securityweek.comMar 11, 2015, 11:37 AM
  • Among the vulnerabilities patched by Microsoft in this month’s Patch Tuesday is one that was supposedly patched back in 2010. The Windows Shell Shortcut Icon Loading Vulnerability (CVE-2010-2568) was one of the four flaws used by the attackers who released the Stuxnet malware against the Iranian nuclear program. “In early January of 2015, researcher Michael Heerklotz approached ZDI with details of a critical vulnerability in the Microsoft Windows operating system. The vulnerability demonstrates that a … More →

    newswww.helpnetsecurity.comMar 11, 2015, 9:36 AM
  • What is old may not always be new, but when it comes to hacking, it’s still effective.

    newswww.securityweek.comFeb 23, 2015, 11:26 PM
  • Researchers with Kaspersky Lab say they have identified the first victims of the infamous Stuxnet worm discovered in 2010.

    newswww.securityweek.comNov 11, 2014, 7:13 PM
  • Experts at Kaspersky discovered that Stuxnet exploits targeting a Windows Shell Vulnerability is still largely used in cyber attacks. Stuxnet has changed the history of malware development, it is considered the fist cyber weapon used by a government in an act of Information Warfare. As remarked by most popular security experts, the militarization of the […]

    newssecurityaffairs.comAug 19, 2014, 6:40 AM
  • It was 2010 when the Stuxnet malware first appeared in the public consciousness. Though the years have passed however, there is no shortage of machines still vulnerable to attacks on one of the vulnerabilities the malware exploited as it trotted across the globe.

    newswww.securityweek.comAug 18, 2014, 11:28 PM
  • As expected a new malware for purposes of cyber espionage was once again identified by the Team of Kaspersky Lab. After Duqu, Flame and Mahdi a new cyber-espionage toolkit has been detected in the same region, the Middle East, and like its predecessor is capable of stealing sensitive data such as online banking credentials, browser passwords and […]

    newssecurityaffairs.comAug 10, 2012, 7:53 AM
  • Don’t worry about zero-days, says MicrosoftHelp Net Security

    Microsoft released its Security Intelligence Report volume 11 (SIRv11), which found that less than 1 percent of exploits in the first half of 2011 were against zero-day vulnerabilities. In contrast, 99 percent of all attacks during the same period distributed malware through familiar techniques, such as social engineering and unpatched vulnerabilities. SIRv11 provides insight into online threat data between January and June 2011 and analysis of data from Internet services and over 600 million computers … More →

    newswww.helpnetsecurity.comOct 11, 2011, 7:58 AM
  • .LNK Exploits – Shortcuts to Insecurity The vulnerability in Windows Shell’s parsing of .LNK (shortcut) files presents some interesting and novel features in terms of its media lifecycle as well as its evolution from zero-day to patched vulnerability. For most of us, the vulnerability first came to light in the context of Win32/Stuxnet, malware that in itself presents some notable quirks.

    newswww.securityweek.comAug 31, 2010, 12:40 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence