Technology

Windows bug remained for years

Security researcher Trend Micros have a weak point in Windows discovered that has been actively exploited for over eight years. So far, however, there are no signs that Microsoft wants to fix the mistake. It is classified as a low risk.

Clear zero-day gap

The attack method is technically simple, but effective: Manipulated .LNK connection files contain hidden commands that download and execute malware when opening. Such commands in Windows are usually easily recognizable. But the hacker groups observed by Trend Micro use a technology in which they fill up the command line arguments with a lot of spaces.

This invisible the harmful instructions in the user interface. Trend Micro reported the security vulnerability to Microsoft in September last year. According to the experts, it has been actively exploited since 2017. After all, the security researchers found almost a thousand manipulated .lnk files, but assume that the actual number of attacks is significantly higher.

“This is one of many security gaps that are used by attackers. But since it has not yet been closed, we have reported it as a Zero-Day Schwachstelle,” Dustin Childs from Zero Day Initiative told the British magazine The Register. Microsoft, on the other hand, rates the matter as a pure user interface problem and not as a real security risk. It could therefore only be remedied in a later Windows version. According to the Trend Micro, around 70 percent of the attacks are manipulated .LNK files from state-supported hacker groups, which mainly operate espionage and data theft.

North Korea is particularly active, which should be responsible for 46 percent of the attacks discovered. Russia, Iran and China each share around 18 percent of the activities. The main goals include government agencies, companies, financial institutions, think tanks and telecommunications companies. The focus is also on the military and the energy sector.

Patch is supposed to come

Trend Micro decided to make the weak point public after Microsoft refused to treat it as a security problem. The combination with other Windows weak spots that could allow an increase in user rights are particularly dangerous. In this case, an entire system could be compromised with comparatively simple means.

In a statement, Microsoft emphasized that the gap did not meet the criteria for immediate correction, but promised a possible consideration in future updates. In addition, the company advises users to exercise caution when downloading files from unknown sources, since Windows already shows security warnings in order to identify potentially harmful files.

Recent Posts

Mouse for MMO players: Razer’s new Naga V3 Pro is a button monster

Razer is launching a new MMO mouse with the Naga V3 Pro. Three magnetic side…

17 hours ago

Surface Phone: New images show discarded Microsoft prototype

It's an open secret that Microsoft was working on a Windows Phone smartphone long before…

17 hours ago

How Solar Carport Structures Are Changing the Future of Sustainable Energy Infrastructure

As the demand for renewable energy continues to grow, businesses, municipalities, and property owners are…

17 hours ago

What to do to find the right family law support in your case.

Family law issues seldom come at an opportune moment. Divorce, separation, parenting conflicts, child support,…

18 hours ago

Claude AI data leak: Private chats were freely accessible on Google

Due to an insufficiently protected sharing function, private chat logs from the Anthropic AI Claude…

1 day ago

Mark Zuckerberg’s megayacht Launchpad ignored calls for help off Alaska

Mark Zuckerberg's $300 million superyacht ignored or allegedly did not hear a call for help…

1 day ago