Windows contains a critical zero-day vulnerability in how certain signed binaries handle the WorkingDirectory parameter when launched via .url shortcut files. Specifically, Windows allows shortcut files to set a working directory that points to an attacker-controlled WebDAV server, which can host malicious executables with the same name as legitimate Windows utilities.
This design flaw allows attackers to trick legitimate Windows processes into loading and executing remote, malicious code without writing anything to disk, leading to stealthy Remote Code Execution (RCE) without requiring user authentication.
| Date | 2025-06-16 16:44:05 |
Technical Summary
Vulnerable Component: The vulnerability resides in the Windows WebDAV client service, in combination with how signed Windows binaries (such as iediagcmd.exe, a diagnostic tool) resolve their dependencies via the WorkingDirectory field in .url files.
Attack Vector: An attacker creates a .url file that:
- Uses a valid path to a legitimate binary in the URL field (e.g., pointing to
iediagcmd.exe) - Sets the WorkingDirectory field to a remote WebDAV share under the attacker’s control
When the user opens this shortcut, Windows launches the trusted binary but looks for dependencies, such as route.exe, in the specified WebDAV folder. If the attacker hosts a malicious version of route.exe in that directory, it is loaded and executed instead of the system one.
Signed binary + malicious working directory = RCE: This combination of trusted code execution with attacker-controlled path resolution constitutes a powerful RCE vector. The malicious executable inherits the permissions of the launched signed binary, often resulting in full user-level compromise.
Unauthenticated Attack: No prior authentication is required. An attacker can distribute the shortcut via spear-phishing emails or compromised web downloads. Once opened, the payload is executed immediately over the network via WebDAV, with no footprint on disk, making detection extremely difficult.
In-the-wild exploitation: Security researchers and Microsoft have confirmed that APT groups (specifically Stealth Falcon/FruityArmor) have been actively using this vulnerability since March 2025. Attackers have used this vector to deploy HorusLoader, which downloaded encrypted implants (Horus Agent) for espionage operations, including keystroke logging, credential dumping, and data exfiltration.
Recommendations
Install June 2025 patches: Microsoft patched CVE-2025-33053 on June 11, 2025, as part of Patch Tuesday. Apply updates to all affected systems, including legacy ones (e.g., Windows Server 2012), as the vulnerability is being actively exploited.
Disable WebDAV if not used: Consider disabling the WebDAV client via Windows features or Group Policy if it is not required. This completely breaks the attack chain.
Restrict Internet access for .url file execution: Block or restrict the execution of
.urlfiles received from untrusted sources, especially if they reference external working directories. Also, monitor.urlfiles that point to WebDAV URLs (e.g.,\\attacker.com\webdav\).Harden the use of LOLBins: Prevent or monitor the use of high-risk signed Windows binaries (e.g.,
iediagcmd.exe,mshta.exe,wscript.exe) via AppLocker or Defender Attack Surface Reduction (ASR) rules, as they are often used in living-off-the-land attacks.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
