New Windows Security Flaw Found, Researchers Claim

Advertisement
By Reuters | Updated: 14 April 2015 10:56 IST
Computer security researchers said they have uncovered a new variation on an old weakness in Microsoft Corp's Windows operating system that could theoretically allow hackers to steal login credentials from hundreds of millions of PCs.

The vulnerability, named 'Redirect to SMB' by security firm Cylance, is similar to one found in the late 1990s that took advantage of a weakness in Windows and Microsoft's Internet Explorer browser which made it possible for attackers to trick Windows into signing on to a server controlled by hackers.

According to Cylance, if a hacker can get a Windows user to click on a bad link in an email or on a website, it can essentially hijack communications and steal sensitive information once the user's computer has logged on to the controlled sever.

In the latest variation of the technique, Cylance said users could be hacked without even clicking on a link, if attackers intercept automated requests to log on to a remote server issued by applications running in the background of a typical Windows machine, for example to check for software updates.

Advertisement

The attack takes advantage of features in Windows Server Message Block, commonly known as SMB. The new variation, discovered by Cylance researcher Brian Wallace, has so far only been recreated in the laboratory and has not been seen on computers in the outside world.

Advertisement

Microsoft said the threat posed by the purported weakness was not as great as Cylance supposed.

"Several factors would need to converge for a 'man-in-the-middle' cyber-attack to occur. Our guidance was updated in a Security Research and Defense blog in 2009, to help address potential threats of this nature," said Microsoft in an emailed statement. "There are also features in Windows, such as Extended Protection for Authentication, which enhances existing defenses for handling network connection credentials."

Advertisement

The CERT unit of the Software Engineering Institute at Carnegie Mellon University, a federally funded body which tracks computer bugs and Internet security issues, issued a warning about the vulnerability on Monday.

It said it was unaware of a full solution to the problem, but suggested several ways of minimizing the vulnerability.

Advertisement

© Thomson Reuters 2015

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Freedom Sale Slashes Prices of Phones, Tablets, and More Products
  2. These OnePlus, Samsung Phones Will Be on Sale During Amazon's Next Sale
  3. These Smartphones Will Be Discounted During Flipkart Republic Day Sale
  4. Here Are Some of the Best Smartphones With Snapdragon 7 Gen 4 SoC
  5. Vivo X200T Confirmed to Launch in India Soon: See Expected Specs
  6. Amazon Great Republic Day Sale 2026: iQOO Smartphone Deals Revealed
  7. Vivo Y500i With a 7,200mAh Battery, 50-Megapixel Camera Launched
  8. Best Laser Printers to Buy in India Right Now
  9. OnePlus 15T New Leak Reveals Colourways, Specifications
  1. iPhone 17 Pro, iPhone 17 Pro Max, iPhone Air Discounts Revealed Ahead of Amazon Great Republic Day Sale 2026
  2. Google’s AI Overviews Giving Incorrect Medical Advice as OpenAI, Anthropic Push for Healthcare: Report
  3. WhatsApp Might Soon Let Parents Control Who Minors Interact With
  4. Nothing Announces Plans to Open Its First Flagship Store in India Soon
  5. After OpenAI, Now Anthropic Introduces Claude for Healthcare AI Tools
  6. Honor Magic 8 RSR Porsche Design Launch Date, Colourways Announced; Set to Arrive Alongside Magic 8 Pro Air
  7. Mahasenha Volume 1 OTT Release Date: When and Where to Watch This Mystical Thriller Online?
  8. Kirkkan OTT Release Date Confirmed: When and Where to Watch it Online?
  9. OnePlus 15T Colourways, RAM, Storage Variants Leaked Online; Tipped to Launch With Snapdragon 8 Elite Gen 5 SoC
  10. Vivo X200T India Launch Teased; Flipkart Availability Confirmed: Expected Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.