Windows PCs infected through big USB security flaw
A new USB security vulnerability has been used in attacks against Windows users, Microsoft warned in a recent security bulletin – issuing a patch for the flaw.
The bug affects all modern versions of Windows, from Vista to Windows 10 – including Windows Server.
Microsoft provided the following details about the vulnerability in security bulletin MS15–085:
An elevation of privilege vulnerability exists when the Mount Manager component improperly processes symbolic links. An attacker who successfully exploited this vulnerability could write a malicious binary to disk and execute it.
To exploit the vulnerability, an attacker would have insert a malicious USB device into a target system. The security update addresses this vulnerability by removing the vulnerable code from the component.
Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft has reason to believe that this vulnerability has been used in targeted attacks against customers.
Ars Technica noted that this vulnerability is similar to a flaw exploited around 2008 by an NSA-tied hacking group called Equation Group, and later by the creators of the Stuxnet computer worm that disrupted Iran’s nuclear programme.
This previous vulnerability was in the functions that process .LNK files, which Windows uses to display icons when a USB drive is plugged in.
The .LNK security flaw can be exploited remotely, but the latest bug seems to require that an infected USB drive be plugged into a Windows machine.
More on Windows 10
Microsoft Windows 10 DVD player app launched – but it might cost you
Unhackable version of Windows being developed
Windows 10 launch a mostly-successful mess
Windows 1.0 to Windows 10: from the first to the last Windows