Microsoft

OneDrive Vulnerability Dispute: Bitdefender Warns, Microsoft Not

The IT security company Bitdefender is currently warning of a malware campaign with which fraudsters are trying to mine cryptocurrencies via a network of hacked PCs. The perfidious thing about it is the security gap – because it is in OneDrive, but Microsoft is not taking action.

Bitdefender had already discovered around 700 attacked Microsoft OneDrive instances in May of this year. A dynamic link library (DLL) sideloading vulnerability in Microsoft OneDrive is exploited. The security company handled this discovery in the familiar manner: They contacted Microsoft, explained their findings and assumed that Microsoft would issue a security update and a warning. But none of that has happened so far.

“Microsoft does not interpret sideloading via a dynamic link library as a security vulnerability,” writes Bitdefender now in the vulnerability disclosure and explained what is behind the discovery and Microsoft’s response.

Performance Affected

First of all, there is an active wave of attacks via the DLL vulnerability in OneDrive. Germany is among the more severely affected countries. The sideloading vulnerability is currently being used to perform crypto mining using the hacked resources. Victims of the hack notice losses in the performance of the systems. However, the vulnerability is also suitable for ransomware attacks or for infection with spyware.

Take Precautionary Measures

Microsoft currently sees no need for action. Cybercriminals exploit a regular feature of the database, so a software update would not be effective. Instead, Microsoft suggests precautionary measures. Users can install Microsoft OneDrive either “per user” or “per machine”. The default is the installation “per user”. In this configuration, users without special privileges can write to the folder in which OneDrive is located.

Hackers can place malicious malware here, modify or completely overwrite executable files. Microsoft, therefore, recommends installing the OneDrive “per machine”. Instructions on how to do this can be found at: https://learn.microsoft.com/en-us/onedrive/per-machine-installation, explains Bitdefender. However, the “per machine” installation is not suitable for everyone. Bitdefender, therefore, warns OneDrive users to be very careful: “Both the virus protection and the operating system used must always be updated.

Recent Posts

Galaxy S27 Pro & S27 Ultra: Samsung plans up to 15% larger batteries

Samsung apparently wants to equip its next high-end smartphones in the classic bar-style form factor…

3 hours ago

iOS 26.6: The iPhone update is now available

Apple has released the update to iOS 26.6 for iPhones. In addition to important security…

3 hours ago

iPhone 18 series: The leanest launch in years is probably imminent

Apple traditionally presents its new iPhones in autumn. However, this year could see buyers have…

3 hours ago

Slightly exaggerated: hobbyist builds crazy alarm system for his Steam Deck

A desperate gamer has built a completely crazy security system for his Steam Deck that…

3 hours ago

Top 5 Interactive AI Avatar Platforms for Real-Time Customer Conversations

What Makes An Interactive AI Avatar Platform Useful? When someone asks, "What is the best…

3 hours ago

End of the PlayStation disc: Angry fans are now planning a mass boycott

The announced disc shutdown on PlayStation is currently heating up fans' minds. While Sony plays…

23 hours ago