Common Weakness Enumeration

    CWE Definition / CWE-64

    CWE-64: Windows Shortcut Following (.LNK)

    The product, when opening a file or directory, does not sufficiently handle when the file is a Windows shortcut (.LNK) whose target is outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-59: Improper Link Resolution Before File Access ('Link Following')

    CWE-64: Windows Shortcut Following (.LNK) | CVE-DB