HomeSecurityWindows 10 S that was "vulnerable to ransomware" hacked

Windows 10 S that was “vulnerable to ransomware” hacked

Windows 10 S Is it completely safe? Microsoft's claim that "no known ransomware" can run on its Windows 10 S operating system appears to be unfounded.

In a Friday post by ZDNet, Hacker House security researcher Matthew Hickey reported that he managed to crack the operating system's security in just over three hours.

Hickey was able to gain remote administrative control and disable various security settings, thus leaving the system open to malware attacks.

Hackey started with an old technique known as DLL injection, where malicious code is executed through a process that system functions consider non-threatening. Windows 10 S

In this particular case, the breach was made with a Word document that contained the embedded macros needed for the hacker to bypass the restrictions on the Windows 10 S operating system that are designed to prevent the use of applications that are not available in the Microsoft Store.

After bypassing Word's protection by downloading the document from a network share – instead of a link or email attachment – ​​Hickey could execute malicious code with administrator privileges.

Using the Metasploit penetration testing software, Hickey was able to gain the highest possible level of access, with system privileges, and repeated the DLL injection to gain remote control of the machine.

After all of this, as you can imagine, Hickey could have installed not just ransomware but any malware he wanted.
The computer, which was one of Microsoft's new Surface Laptops, was completely vulnerable.

Microsoft, meanwhile, dismissed ZDNet's claim, saying its own testing proved that Windows 10 S is not vulnerable to ransomware attacks.

"In early June, we stated that Windows 10 S is not vulnerable to any known ransomware," a company spokesperson said.

And he said:

“We recognize that new attacks and malware are constantly emerging, so we are committed to monitoring the threat landscape and working with responsible researchers to ensure that Windows 10 continues to provide the most secure experience for our customers.”

Clearly, based on Hickey's testing, Microsoft's claim doesn't seem to hold up. While Windows 10 S may be less vulnerable to such attacks because it will only run strictly tested software approved by Microsoft, there are still ways that it can infect computers running that operating system.

Microsoft implying that its operating system is immune to all “known ransomware” was not so wise. The strong security claims invite challenge.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS