CVE detail
CVE-2010-2568
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
23 source links · newest first
Our telemetry shows a surge in Windows shortcut (LNK) malware use. We explain how attackers exploit LNK files for malware delivery.
vendorunit42.paloaltonetworks.comJul 2, 2025, 10:00 AMThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including the bug used in the Stuxnet attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six new vulnerabilities to its Known Exploited Vulnerabilities Catalog. Below is the list of vulnerabilities added to the catalog: CVE-2022-40139: Trend […]
newssecurityaffairs.comSep 17, 2022, 3:11 PMAn analysis of 17 espionage frameworks designed to target air-gapped networks shows that all of them leverage USB drives and all target Windows exclusively, ESET reports.
newswww.securityweek.comDec 3, 2021, 12:20 PM- Microsoft Attempts To Fix Stuxnet For The Third TimeSecurity Affairs
Microsoft released a new security update on June 17th in an attempt to patch a vulnerability which allowed the Stuxnet Virus to exploit Windows systems. The Stuxnet Virus which attacks Industrial Control Systems was first discovered in 2010 when it infected Iranian Programmable Logic Controllers. Stuxnet compromises controllers by first targeting Windows operating systems and […]
newssecurityaffairs.comAug 4, 2017, 6:22 PM One of the patches released by Microsoft as part of its June 2017 security updates represents the company’s third attempt at patching an old vulnerability exploited by the notorious Stuxnet worm in 2010.
newswww.securityweek.comAug 4, 2017, 12:39 PMWikiLeaks published several documents on Thursday detailing a tool allegedly used by the U.S. Central Intelligence Agency (CIA) to hack air-gapped networks through USB drives.
newswww.securityweek.comJun 23, 2017, 7:20 AMA report published by Kaspersky Lab on Thursday shows that the number of attacks involving exploits increased significantly in 2016 compared to the previous year, but the number of attacked users actually dropped.
newswww.securityweek.comApr 21, 2017, 1:47 PM- The Stuxnet vulnerability is still one of the most exploited flaws in the wild by hackersSecurity Affairs
A new report published by Kaspersky confirms that Stuxnet exploits targeting a Windows Shell Vulnerability is still widely adopted by threat actors. The case that I’m going to present to you demonstrates the importance of patch management and shows the effects of the militarization of cyberspace. Unpatched software is an easy target for hackers that can exploit […]
newssecurityaffairs.comApr 21, 2017, 1:10 PM - Attacks exploiting software vulnerabilities are on the riseHelp Net Security
Attacks conducted with the help of exploits are among the most effective as they generally do not require any user interaction, and can deliver dangerous code without arousing user suspicion. According to data gathered by Kaspersky Lab, there were 702 million attempts to launch an exploit in 2016 – an increase of 24.54 percent from 2015. During the same period, more than 297,000 users worldwide were attacked by unknown exploits (zero-day and heavily obfuscated known … More →
newswww.helpnetsecurity.comApr 21, 2017, 12:50 PM Users that run unpatched software beware. Hackers have been relying on an old software bug tied to the Stuxnet worm to carry out their attacks. Microsoft may have initially patched the flaw in 2010, but it’s nevertheless become the most widespread software exploit, according to security firm Kaspersky Lab. On Thursday, Kaspersky posted research examining […]
newswww.csoonline.comApr 20, 2017, 9:01 PM- Exploit kits are the greatest danger for Windows usersHelp Net Security
Exploit kits are how most malware gets on victims’ computers and, according to Microsoft, encounters with exploit kits increased by more than a third from 3Q15 to 4Q15. The second place on the list of exploits most commonly detected and blocked by Microsoft real-time antimalware products in 2H15 is the one for CVE-2010-2568, the Windows Shell Shortcut Icon Loading Vulnerability which was one of the four flaws used by the attackers who released the Stuxnet … More →
newswww.helpnetsecurity.comMay 9, 2016, 3:07 PM The most commonly targeted vulnerability in 2015 was a Windows flaw that came to light in 2010 after being exploited by the notorious Stuxnet malware, Microsoft said in its latest Security Intelligence Report (SIR).
newswww.securityweek.comMay 6, 2016, 3:50 PMSecurity researchers have teamed up with the law enforcement community for another takedown of a malware network.
newswww.securityweek.comApr 9, 2015, 5:00 PM- Microsoft tries to fix again LNK flaw exploited by StuxnetSecurity Affairs
A security bulletin recently released by Microsoft addresses the LNK flaw that was exploited by Stuxnet and that we have wrongly considered patched since 2010. If you followed IT in the last few years, you might remember that Stuxnet was discovered around mid-2010 and at the time it was used against the Iranian nuclear program. […]
newssecurityaffairs.comMar 13, 2015, 7:11 AM One of the security bulletins released by Microsoft on Tuesday addresses a vulnerability that should have been patched since August 2010.
newswww.securityweek.comMar 11, 2015, 11:37 AM- Microsoft patches flaw exploited by Stuxnet – againHelp Net Security
Among the vulnerabilities patched by Microsoft in this month’s Patch Tuesday is one that was supposedly patched back in 2010. The Windows Shell Shortcut Icon Loading Vulnerability (CVE-2010-2568) was one of the four flaws used by the attackers who released the Stuxnet malware against the Iranian nuclear program. “In early January of 2015, researcher Michael Heerklotz approached ZDI with details of a critical vulnerability in the Microsoft Windows operating system. The vulnerability demonstrates that a … More →
newswww.helpnetsecurity.comMar 11, 2015, 9:36 AM What is old may not always be new, but when it comes to hacking, it’s still effective.
newswww.securityweek.comFeb 23, 2015, 11:26 PM- First Stuxnet Victims Unmasked in ResearchSecurityWeek
Researchers with Kaspersky Lab say they have identified the first victims of the infamous Stuxnet worm discovered in 2010.
newswww.securityweek.comNov 11, 2014, 7:13 PM - Kaspersky revealed that Stuxnet Exploits is still used worldwideSecurity Affairs
Experts at Kaspersky discovered that Stuxnet exploits targeting a Windows Shell Vulnerability is still largely used in cyber attacks. Stuxnet has changed the history of malware development, it is considered the fist cyber weapon used by a government in an act of Information Warfare. As remarked by most popular security experts, the militarization of the […]
newssecurityaffairs.comAug 19, 2014, 6:40 AM It was 2010 when the Stuxnet malware first appeared in the public consciousness. Though the years have passed however, there is no shortage of machines still vulnerable to attacks on one of the vulnerabilities the malware exploited as it trotted across the globe.
newswww.securityweek.comAug 18, 2014, 11:28 PMAs expected a new malware for purposes of cyber espionage was once again identified by the Team of Kaspersky Lab. After Duqu, Flame and Mahdi a new cyber-espionage toolkit has been detected in the same region, the Middle East, and like its predecessor is capable of stealing sensitive data such as online banking credentials, browser passwords and […]
newssecurityaffairs.comAug 10, 2012, 7:53 AM- Don’t worry about zero-days, says MicrosoftHelp Net Security
Microsoft released its Security Intelligence Report volume 11 (SIRv11), which found that less than 1 percent of exploits in the first half of 2011 were against zero-day vulnerabilities. In contrast, 99 percent of all attacks during the same period distributed malware through familiar techniques, such as social engineering and unpatched vulnerabilities. SIRv11 provides insight into online threat data between January and June 2011 and analysis of data from Internet services and over 600 million computers … More →
newswww.helpnetsecurity.comOct 11, 2011, 7:58 AM - Shortcuts to Insecurity: .LNK ExploitsSecurityWeek
.LNK Exploits – Shortcuts to Insecurity The vulnerability in Windows Shell’s parsing of .LNK (shortcut) files presents some interesting and novel features in terms of its media lifecycle as well as its evolution from zero-day to patched vulnerability. For most of us, the vulnerability first came to light in the context of Win32/Stuxnet, malware that in itself presents some notable quirks.
newswww.securityweek.comAug 31, 2010, 12:40 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2014-1776CVSS 9.8 · Critical
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vec…
- CVE-2014-0315CVSS 6.9 · Medium
Untrusted search path vulnerability in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,…
- CVE-2014-0323CVSS 6.6 · Medium
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8…
- CVE-2014-0301CVSS 9.3 · Critical
Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7…
- CVE-2014-0300CVSS 7.2 · High
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8…
- CVE-2014-0266CVSS 7.1 · High
The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows…