CPLINK and Win32/CplLnk.A are names for a Microsoft
Windows shortcut icon
vulnerability discovered in June 2010 and patched on 2 August that affected all Windows operating systems. The vulnerability is exploitable when any Windows application that display shortcut icons, such as
Windows Explorer,
browses to a folder containing a malicious shortcut.
The exploit can be triggered without any user interaction, regardless where the shortcut file is located.
In June 2010,
VirusBlokAda
VBA32 (Virus Block Ada 32) is antivirus software from the vendor VirusBlokAda for personal computers running Microsoft Windows. It detects and neutralizes computer viruses, computer worms, Trojan horses and other malware (backdoors, adware, spyw ...
reported detection of
zero-day attack malware called
Stuxnet that exploited the vulnerability to install a
rootkit that snooped
Siemens
Siemens AG ( ) is a German multinational conglomerate corporation and the largest industrial manufacturing company in Europe headquartered in Munich with branch offices abroad.
The principal divisions of the corporation are ''Industry'', '' ...
'
SCADA
Supervisory control and data acquisition (SCADA) is a control system architecture comprising computers, networked data communications and graphical user interfaces for high-level supervision of machines and processes. It also covers sensors and ...
systems
WinCC and
PCS 7
A personal computer (PC) is a multi-purpose microcomputer whose size, capabilities, and price make it feasible for individual use. Personal computers are intended to be operated directly by an end user, rather than by a computer expert or techn ...
. According to
Symantec Symantec may refer to:
*An American consumer software company now known as Gen Digital Inc.
*A brand of enterprise security software purchased by Broadcom Inc.
Broadcom Inc. is an American designer, developer, manufacturer and global supplier ...
it is the first worm designed to reprogram industrial systems and not only to spy on them.
References
{{Reflist
External links
Microsoft Security Advisory (2286198)concerning the Windows vulnerability exploited by CPLINK.
Infoworld articleIs Stuxnet the 'best' malware ever?
Injection exploits
Malware