A. Since this is a design issue, in the way how Shortcut’s are parsed, no malicious payload (shellcode) is required to exploit this flaw. The LNK file needs to point to a malicious file, the path of which needs to be hardcoded in the Shortcut file.
...
more