HomeSecuritySecurity flaw in Windows allows access to any application!

Windows security flaw allows access to any application!

[su_heading size=”18″]If you think your Windows computer network is safe from malware because you have Applocker installed to whitelist only trusted applications, we have bad news! [/su_heading]

Windows
The vulnerability was discovered last week by Casey Smith from Colorado.

A recently discovered security flaw allows users to exploit it in business versions of Windows (Windows 7 and later) using Regsvr32. They can use it in a remotely hosted file or script and run any application they want on your system. 

[su_button url=”https://www.secnews.gr/103463/windows-powershell-google-docs-diadidoun-laziok-trojan/” target=”blank” style=”glass” background=”#58ce35″ color=”#1218126″ wide=”yes” center=”yes” radius=”round” icon_color=”#ffffff”]Windows PowerShell and Google Docs Spread Laziok Trojan[/su_button]

This exposes computers to the risk of malware running even if Applocker is installed. And since it doesn't require administrator access or modifying the system registry, it's very difficult to detect.

The vulnerability was discovered last week by Casey Smith from Colorado, who blogged about his findings and published proof-of-concept scripts to demonstrate it on GitHub.

[su_button url=”https://www.secnews.gr/103231/ereunitis-anagnwrizei-xss-filtro-pou-parakamptei-ton-microsoft-edge/” target=”blank” style=”bubbles” background=”#123be9″ color=”#eceeec6″ wide=”yes” center=”yes” radius=”round” icon_color=”#ffffff”]Researcher identifies XSS filter that bypasses Microsoft Edge[/su_button]

Microsoft has not yet released a patch. For now, the CSO notes that you can disable network awareness of Regsvr32.exe and Regsvr64.exe using Windows Firewall.

Other researchers said that Device Guard, which is fully enabled with script protection, can block the bypass as well, but this requires the enterprise to have Windows 10 Enterprise and Hyper-V on the system in question.

Now we await Microsoft's response and a fix for the problem.

[su_button url=”https://www.secnews.gr/103477/epithesi-twn-anonymous-stin-istoselida-tis-ku-klux-klan/” target=”blank” style=”bubbles” background=”#e9121b” color=”#1218126″ wide=”yes” center=”yes” radius=”round” icon_color=”#ffffff”]Anonymous attack on the Ku Klux Klan website![/su_button]

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS