New Windows Security Flaw Found, Researchers Claim

Advertisement
By Reuters | Updated: 14 April 2015 10:56 IST
Computer security researchers said they have uncovered a new variation on an old weakness in Microsoft Corp's Windows operating system that could theoretically allow hackers to steal login credentials from hundreds of millions of PCs.

The vulnerability, named 'Redirect to SMB' by security firm Cylance, is similar to one found in the late 1990s that took advantage of a weakness in Windows and Microsoft's Internet Explorer browser which made it possible for attackers to trick Windows into signing on to a server controlled by hackers.

According to Cylance, if a hacker can get a Windows user to click on a bad link in an email or on a website, it can essentially hijack communications and steal sensitive information once the user's computer has logged on to the controlled sever.

In the latest variation of the technique, Cylance said users could be hacked without even clicking on a link, if attackers intercept automated requests to log on to a remote server issued by applications running in the background of a typical Windows machine, for example to check for software updates.

Advertisement

The attack takes advantage of features in Windows Server Message Block, commonly known as SMB. The new variation, discovered by Cylance researcher Brian Wallace, has so far only been recreated in the laboratory and has not been seen on computers in the outside world.

Advertisement

Microsoft said the threat posed by the purported weakness was not as great as Cylance supposed.

"Several factors would need to converge for a 'man-in-the-middle' cyber-attack to occur. Our guidance was updated in a Security Research and Defense blog in 2009, to help address potential threats of this nature," said Microsoft in an emailed statement. "There are also features in Windows, such as Extended Protection for Authentication, which enhances existing defenses for handling network connection credentials."

Advertisement

The CERT unit of the Software Engineering Institute at Carnegie Mellon University, a federally funded body which tracks computer bugs and Internet security issues, issued a warning about the vulnerability on Monday.

It said it was unaware of a full solution to the problem, but suggested several ways of minimizing the vulnerability.

Advertisement

© Thomson Reuters 2015

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 16 Pro, iPhone 16 Pro Max Offers Listed Ahead of Flipkart Sale
  2. iPhone 17 Series, iPhone Air Pre-Order Discounts Announced by Retailers in India
  3. Instamart Sale: iPhone 16, OnePlus 13R at Jaw-Dropping Prices
  4. OnePlus 13 Gets Big Price Cut at Amazon Great Indian Festival Sale
  5. Google Pixel 10 Review: A Brilliant Phone We Wanted to Love
  6. WhatsApp Now Lets You Set Notification Reminders for Messages
  7. Early Deals on PlayStation 5 and Accessories Revealed Ahead of Amazon Sale
  8. YouTube Announces New AI Tools for Shorts Creators, Podcasters, Live Streamers
  9. Redmi 15R 5G With MediaTek Dimensity 6300 SoC, 6,000mAh Battery Launched
  10. Oppo Find X9 Pro Chipset, AnTuTu and Geekbench Scores Revealed
  1. Assassin's Creed IV: Black Flag Remake Will Reportedly Feature RPG Mechanics, Launch in Early 2026
  2. Amazon Sale 2025: OnePlus 13 Deal We've All Been Waiting For Is Finally Here
  3. Instamart Quick India Movement Sale 2025 Goes Live on September 19 With Jaw-Dropping Prices on iPhone 16, OnePlus 13R, and More
  4. Redmi 15R 5G Launched With MediaTek Dimensity 6300 SoC, 6,000mAh Battery: Price, Specifications
  5. Bitcoin Climbs to $116,700 as Ethereum, Altcoins Consolidate Ahead of US Fed Policy Decision
  6. iPhone 17 Series Might Only Support Faster Charging With Apple’s New 60W Adaptor For Limited Time
  7. Xiaomi 15T Specifications Leaked; Tipped to Launch With MediaTek Dimensity 8400 Ultra SoC
  8. WhatsApp for iOS Adds Notification Reminders for Messages, Meetings, and Deadlines
  9. Palworld to Exit Early Access, Get Version 1.0 Release in 2026, Pocketpair Announces
  10. Samsung Galaxy S26 Ultra With Redesigned Camera Module Seen in Leaked Case Renders
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.