We've previously covered the dangers of using a USB drive you find on the street. It could contain malware that targets your online accounts. Bitdefender security researcher Marius Tivadar highlighted the importance of this issue with proof-of-concept code (Via: CSO Online).
When you insert an unknown USB stick into your computer (which contains this code), this malicious code can cause the infamous Blue Screen of Death (BSOD) on Microsoft's Windows operating systems. The flaw it exploits in this case has to do with how Windows handles NTFS images.
On the GitHub page , Tivadar describes how someone can trigger a BSOD using a “handcrafted NTFS image.” Furthermore, this denial of service can be triggered by admin, limited user account, or user mode. “It can cause the system to crash even if it is locked.”
The affected versions of Windows (although not limited to) that can be targeted by this attack are:
- Windows 7 Enterprise 6.1.7601 SP1, Build 7601 x 64
- Windows 10 Pro 10.0.15063, Build 15063 x64
- Windows 10 Enterprise Evaluation Insider Preview 10.0.16215, Build 16215 x64
The GitHub report also describes the method of preparing NTFS images. After the attack, auto-play is activated and the system automatically crashes.
If auto-play takes action, the attack can take place even when the system is locked. Tivadar believes this behavior should be discouraged.
The researcher notified Microsoft about the issue, but the company did not initiate a CVE (Common Vulnerabilities and Exposures) or issue an official patch. However, the company did patch the issue at some point without informing Tivadar. As a result, the BSOD code attack is not possible in the recent Windows 10 Build 16299.
