New Windows Security Flaw Found, Researchers Claim

Advertisement
By Reuters | Updated: 14 April 2015 10:56 IST
Computer security researchers said they have uncovered a new variation on an old weakness in Microsoft Corp's Windows operating system that could theoretically allow hackers to steal login credentials from hundreds of millions of PCs.

The vulnerability, named 'Redirect to SMB' by security firm Cylance, is similar to one found in the late 1990s that took advantage of a weakness in Windows and Microsoft's Internet Explorer browser which made it possible for attackers to trick Windows into signing on to a server controlled by hackers.

According to Cylance, if a hacker can get a Windows user to click on a bad link in an email or on a website, it can essentially hijack communications and steal sensitive information once the user's computer has logged on to the controlled sever.

Advertisement

In the latest variation of the technique, Cylance said users could be hacked without even clicking on a link, if attackers intercept automated requests to log on to a remote server issued by applications running in the background of a typical Windows machine, for example to check for software updates.

The attack takes advantage of features in Windows Server Message Block, commonly known as SMB. The new variation, discovered by Cylance researcher Brian Wallace, has so far only been recreated in the laboratory and has not been seen on computers in the outside world.

Advertisement

Microsoft said the threat posed by the purported weakness was not as great as Cylance supposed.

"Several factors would need to converge for a 'man-in-the-middle' cyber-attack to occur. Our guidance was updated in a Security Research and Defense blog in 2009, to help address potential threats of this nature," said Microsoft in an emailed statement. "There are also features in Windows, such as Extended Protection for Authentication, which enhances existing defenses for handling network connection credentials."

Advertisement

The CERT unit of the Software Engineering Institute at Carnegie Mellon University, a federally funded body which tracks computer bugs and Internet security issues, issued a warning about the vulnerability on Monday.

It said it was unaware of a full solution to the problem, but suggested several ways of minimizing the vulnerability.

Advertisement

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1.  Xiaomi 18, 18 Pro and 18 Pro Max Specifications Leaked Ahead of Debut
  2. Honor X7e With a 7,500mAh Battery Debuts Globally at This Price
  3. Vivo X500 Pro Max Display and Battery Details Revealed in New Leak
  4. RTX Spark-Powered Laptops Could Cost a Lot More Than Regular AI PCs
  5. God of War Laufey Revealed at State of Play: Everything You Need to Know
  6. Realme P4R 5G India Launch Date, Design and Key Specifications Revealed
  7. Lumio Launches 55-Inch Variants of Vision 9 (2026), Vision 7 (2026) in India
  1. UK's FCA Warns Premier League Clubs Over Unauthorised Crypto Sponsor Risks
  2. Vivo X500 Pro Max Display and Battery Details Surface Online in Early Leak; Largest Model Said to Feature 6.85-Inch Screen
  3. Google Introduces Fake Call Detection for Android Phones to Curb Call Spoofing Attacks
  4. Google Rolls Out Gemini Thinking Levels Across Platforms With 'Extended' Thinking Mode for All Users
  5. Samsung Galaxy A27 Reportedly Bags US FCC Certification Ahead of Anticipated Launch
  6. NYDFS, European Banking Authority Join Forces to Oversee, Monitor Stablecoin Activities
  7. Meta Reportedly Testing ‘Series’ Feature to Organise Instagram, Facebook Reels Into Episodic Collections
  8. Xiaomi 18 Tipped to Sport 6.4-Inch Display; Pro Models Said to Feature Dual 200-Megapixel Rear Cameras
  9. Realme P4R 5G India Launch Date Revealed Along With Design and Key Specifications
  10. Marvel's Wolverine Gets Visceral Gameplay Trailer at State of Play, Pre-Orders Now Live
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.