Security12.08.2015

Windows PCs infected through big USB security flaw

Windows logo

A new USB security vulnerability has been used in attacks against Windows users, Microsoft warned in a recent security bulletin – issuing a patch for the flaw.

The bug affects all modern versions of Windows, from Vista to Windows 10 – including Windows Server.

Microsoft provided the following details about the vulnerability in security bulletin MS15–085:

An elevation of privilege vulnerability exists when the Mount Manager component improperly processes symbolic links. An attacker who successfully exploited this vulnerability could write a malicious binary to disk and execute it.

To exploit the vulnerability, an attacker would have insert a malicious USB device into a target system. The security update addresses this vulnerability by removing the vulnerable code from the component.

Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft has reason to believe that this vulnerability has been used in targeted attacks against customers.

Ars Technica noted that this vulnerability is similar to a flaw exploited around 2008 by an NSA-tied hacking group called Equation Group, and later by the creators of the Stuxnet computer worm that disrupted Iran’s nuclear programme.

This previous vulnerability was in the functions that process .LNK files, which Windows uses to display icons when a USB drive is plugged in.

The .LNK security flaw can be exploited remotely, but the latest bug seems to require that an infected USB drive be plugged into a Windows machine.

Microsoft Windows 10 DVD player app launched – but it might cost you

Unhackable version of Windows being developed

Windows 10 launch a mostly-successful mess

Windows 1.0 to Windows 10: from the first to the last Windows

How to install Windows 10

Show comments

Latest news

More news

Trending news

Poll

What is your preferred smart home camera brand?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter