Windows closes a 23-year-old vulnerability: custom folder icons no longer supported

Every Patch Tuesday, Microsoft gives us a reason to discuss the latest Windows update that has caused problems. This time, however, the situation is different: a new security update has actually fixed an issue, even if it has disrupted an old feature. When Windows users noticed that their custom folder icons had stopped working, it seemed like another botched Windows update. In reality, however, these missing icons are the result of a deliberate security fix that has been present in Windows for a long time. Microsoft has finally decided that this small feature could no longer be trusted.

Windows stops trusting desktop.ini files

For years, Windows has used a small hidden file called desktop.ini to control the appearance of folders within File Explorer. This file made custom folder icons, localized folder names, and countless icon packs possible. As long as a folder contained the right desktop.ini and the icon resource, Explorer displayed it without a second thought. Unfortunately, it also trusted that metadata in the same way, including files from downloaded archives, WebDAV shares, and other Web-Marked sources.

Every file downloaded from the Internet, Windows attaches a hidden metadata identifier, considering it potentially unsafe. This security feature is called the Mark of the Web (MoTW).

Microsoft has highlighted how threat actors, including the Vietnam-linked OceanLotus group, had abused desktop.ini to disguise malicious folders and make them appear far more trustworthy than they actually were. Attackers exploiting this security bug have historically abused Explorer's willingness to passively accept cosmetic metadata, regardless of how unverified its source was.

That's what the June 2026 security update has changed. Windows now refuses to honor untrusted desktop.ini files. Microsoft has been clear that the disruption of custom folder icons as a consequence of this change was not an unintended regression, but rather a deliberate fix for a security weakness whose roots trace back to a vulnerability first identified in 2003.

A Windows XP-era vulnerability finally comes to an end

This security issue was so old it could buy beer. The story begins in 2003, when Microsoft disclosed and patched a vulnerability tracked as MS03-027. Although the original defect had been fixed, it exposed a broader problem that persisted for decades: Windows Explorer's willingness to trust presentation-related metadata more than it probably should. Hidden within that trust model was an unchecked buffer in the same Shell function responsible for parsing desktop.ini, and it didn't take much to trigger it. Simply navigating to a folder was enough to activate it, without any download prompts, clicks, or files involved. Navigating to that folder was enough. Simply navigating to a folder was enough to activate it, without any download prompts, clicks, or files involved. Navigating to that folder was enough.

There are also other ways to achieve the same result. For example, you can use the attrib +s +h command to hide the desktop.ini file, or you can use the attrib +r command to set the read-only attribute on the folder. Alternatively, you can use a registry editor to modify the Hidden value for the desktop.ini file.

Windows 10

While the loss of custom folder icons may be frustrating for some users, it's important to remember that this change was made to improve Windows' security. By closing a 23-year-old attack surface, Microsoft is taking an important step to protect its users from potential threats. And with the methods described above, advanced users can still customize their folder icons if they wish.

Impact on the IT sector and future considerations

Microsoft's decision to close this vulnerability has significant implications for the IT sector. On one hand, system administrators and software developers will need to update their practices to ensure compatibility with this change. For example, folder icon management tools will need to be updated to respect the new security restrictions.

On the other hand, this change could stimulate innovation in the field of user interface customization. Developers might explore new solutions to offer similar functionality without compromising security. For example, tools that allow setting custom icons in a secure way, using Microsoft-approved methods, could be developed.

Considerations for business users

For businesses using Windows, this change might require an update of security policies and operating procedures. System administrators should assess the impact of this change on their environments and ensure that all critical folders have appropriate and secure icons.

Additionally, businesses might want to train their employees on the new procedures for managing folder icons. This could include training on how to use the PowerShell commands described in the first part of the article or how to use approved third-party tools.

The future of customization in Windows

Microsoft's decision to sacrifice a customization feature for improved security raises questions about the future of customization in Windows. While security is an absolute priority, users appreciate the ability to customize their work environment.

Microsoft might explore alternative solutions to offer customization features without compromising security. For example, they could develop a folder icon system based on approved extensions or a secure icon repository. This would allow users to customize their icons without exposing the system to potential vulnerabilities.

Microsoft's decision to close a 23-year-old vulnerability is an important step to improve Windows' security. However, this change has a significant impact on users who use custom icons. It is important that users and businesses adapt to this change and explore alternative solutions for folder icon customization.

This change underscores the importance of balancing security and functionality. While security must always be a priority, it is also important to find ways to offer users the flexibility they need to customize their work environment. Over time, we hope that Microsoft and the developer community will find innovative solutions to address this challenge.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.