A patch is planned fro released today by Microsoft. The out of band security update is to address the windows shortcut vulnerability.
Caused by an error in the windows shell when parsing shortcuts (.lnk), the flaw can be exploited automatically by executing code via a booby trapped shortcut. Certain parameters of the .lnk are not properly validated on load, resulting in the vulnerability. According to Microsoft attacks have been targeted and limited for this vulnerability.
A Fixit solution was released last week for users to protect against attacks. but applying the Fixit removed the icons from shortcuts on the taskbar and start menu. But this was not an ideal solution fro most users, so Microsoft picked up the pace to release an out of band fix.
Christopher Budd, Microsoft Security Response Manager, said the following:
"We are releasing the bulletin as we’ve completed the required testing and the update has achieved the appropriate quality bar for broad distribution to customers. Additionally, we’re able to confirm that, in the past few days, we’ve seen an increase in attempts to exploit the vulnerability. We firmly believe that releasing the update out of band is the best thing to do to help protect our customers,"
The update will be released later today, just over a week before Patch Tuesday.
