A file on a USB key is enough to crash Windows


A hacker has found a way to make system snapshots that can instantly bring Windows 7 and Windows 10 to the knees. Oddly, Microsoft does not intend to fix this bug.

Good news for little jokers. Security researcher Marius Tivadar of Bitdefender has released a method on GitHub to crash Windows using a simple file. The expert, in fact, found a flaw in the way Windows handles NTFS system images. He found the bug in July 2017 and immediately alerted Microsoft, but Microsoft did not see fit to fix it. To cause the breakdown, it would indeed "physical access or attack by social engineering," writes the company Redmond in an email. In short, it would not be dangerous enough to develop a patch.

Still, this bug is extremely simple to reproduce. Simply put the trapped file of an NTFS system image on a USB stick and insert it into a Windows PC. The researcher has published a file of this type on GitHub with a size of 10 MB. If auto-play is enabled, the system crashes immediately, whether the session is locked or not.

If auto-play is not enabled, the crash will occur if the system attempts to access the trap file. For example, during a security scan or if the user clicks on the system image. An attacker could also spread the code in a malware to cause mass crashes. "I really believe that this behavior should be changed," says Marius Tivadar in a PDF document that gives all the technical details of this bug.

The researcher has seen the flaw on Windows 7 Build 7601 and Windows 10 Build 15063 and Build 16215. The latest versions of Windows 10 do not seem to be affected, but the researcher could not have had the time to check it.

Source: Bleeping Computers

paypal,facebook,yahoo,mail,google,maps,ebay,amazon,barcelone,realmadrid,netflix,craigslist,AliCarter,Liverpool,AlfieEvans,YankeesVsAngels,RonanFarrow,YeVsThePeople,MesotheliomaLawFirm,Donate,CarToCharity,California,Donate,Car,ForTaxCredit,DonateCarsInMa;Insurance,Loans,Mortgage,Attorney,Credit,Lawyer,Donate,Degree,Hosting,Claimcashfear,softwares,money,football,SPORTNEWS,cars,carrental,cellphone,phonenumber,forex,torrent,voip,net,adsence,tollsspeakers,tipsspeakers,iphonespeakers,phones,iphone4,facebook,youtube,twitter,livematch,newslive,watchmatchforfree,watchlaligaforfree,watchserieAliveonjsc+,softwares,football,SPORTNEWS,cars,carrental,cellphone,phonenumber,forex,torrent,voip,net,adsence,tollsspeakers,tipsspeakers,iphonespeakers,phones,iphone4,facebook,youtube,twitter,livematch,newslive,watch match for free,watch laliga for free,watch serie A live on jsc+,windows 7,windows 8

Commentaires

CALL US

Nom

E-mail *

Message *

Posts les plus consultés de ce blog

Dolby Digital, Atmos or DTS ... what do these audio technologies hide?

2️⃣لغز جو بايدن وسره مع اللقاح💉كشف الرقم㊙️ المرحلة القادمة 2022تهيئوا🚪BIDEN THE SECRET NUMBER PLAN

Snapchat now allows you to delete any message sent