One Day Sec

What interesting behavior was discovered when combining .lnk files with .cab archives?

When a `.lnk` file is packed into a `.cab` and extracted, then saved, a warning appears. However, if you right‑click the extracted `.lnk` to view its properties and then open it again, the warning disappears and the ADS is cleared. This bug exists in Win10 Build 10586 and earlier, and was fixed in Build 14393 (1607). The `.lnk` itself can also be obfuscated by hiding its arguments with spaces, as detailed in the linked article An interesting way of bypassing Windows Attachment Manager.
lnk filecab archiveADS clearingpropertiesbypassWindows Attachment Manager bug

Browse all Q&A →