One of the most revolutionary features that Windows 10 brought when it was released was the revamped look of the Windows Settings app, which was designed to be more user-friendly. However, with the implementation of the new look, researchers report that Microsoft inadvertently added a major security hole.

According to Matt Nelson, a security researcher at SpecterOps, the “.SettingContent-ms” file type is suspicious. This file type was introduced in Windows 10 in 2015, and its purpose was to create shortcuts to the Settings Page of the operating system. The idea was that after the change, the Windows Control Panel would be more user-friendly than in previous versions of the operating system.
The problem is that these shortcuts are created as XML files which are quite easy to edit, and lead to some powerful tool like Command Prompt and Powershell.
Malicious users can change the shortcuts and call other programs, or even more than one program. The user may not know that anything has changed on their system.
However, the most worrying fact is that .SettingContent-ms file types are not checked by either the built-in Windows Defender or the Office Attack Surface Reduction Tool. There is a fear that such files can be embedded in Office documents.
As Nelson states (and shows in the video evidence), “when the file comes from the internet, it is executed when the “Open” option is selected, without displaying any notification or asking for permission from the user. The problem has been reported to Microsoft, but they do not see it as a vulnerability as no malicious activity has been reported so far.
[su_youtube url=”https://www.youtube.com/watch?v=E4ywhiS8vF8″ width=”640″ height=”380″]https://www.youtube.com/watch?v=B7o0qA4L4So[/su_youtube]
