"All you do is open a device/network share/WebDav point that has the shortcut, and boom! It runs whatever you tell it to," said Sophos Senior Security Advisor Chester Wisniewski. "It is downright simple to exploit. Any criminal with the most basic of skills can take advantage of this flaw. We have not seen much activity in the wild yet, but now that a proof of concept is posted it is likely to become a major issue as the week rolls on."
During the weekend of July 17, a security researcher going by the moniker Ivanlef0u published a working exploit for the flaw, which was already being used to infect computers via USB drives with malware known as Stuxnet.