Windows 10 October 2018 Update Hit by ZIP File Bug Spotted Months Before Release

Advertisement
By Gadgets 360 Staff | Updated: 24 October 2018 19:04 IST
Highlights
  • This is one of several bugs found in Windows 10 October 2018 Update
  • In the meanwhile, a zero-day vulnerability has been publicly outed
  • The vulnerability could be misused by malware authors before a patch

Windows 10 October 2018 Update has been riddled with bugs since launch

Windows 10 October 2018 Update's launch was rocky to say the least, with bugs popping up immediately after release, and one severe enough to delete user data upon installation. This caused Microsoft to suspend the rollout until it could fix the issue, and industry-wide outrage at the lack of quality control on part of the Redmond giant in fixing bugs that had already been spotted in preview stages. Now it appears Windows 10 October 2018 Update (aka Windows 10 version 1809) has been hit with another bug related to ZIP archives. In the meanwhile, a security researcher has publicly outed a zero-day vulnerability in Windows 10, Windows Server 2016, and Windows Server 2019. A patch for this vulnerability has yet to be rolled out by Microsoft.

First spotted by a Reddit user, the Windows 10 October 2018 Update contains a bug related to extracting/ pasting files from a ZIP archive when using the native Windows File Explorer tool. If a user tries to extract or paste a file (let's say, gadgets360.jpg) from inside a ZIP archive into another folder containing another file with the same name (gadgets360.jpg), they will not be given an overwrite prompt. Instead, the destination folder file's modified date changes, but the file is not replaced at all.

Windows 10 October 2018 Update Patch Now Giving Blue Screen of Death Issues, Some Users Report

Advertisement

While this doesn't sound as serious as the data-loss bug, and doesn't actually overwrite the file, it is severe if one counts the use case where the original ZIP file is deleted by a user convinced they have replaced files. It also misleads users into believing there was no file in the destination folder that matched with files in the ZIP archive. Another Reddit user, who added that the bug also has the Windows File Explorer showing file transfer progress, corroborates the bug.

Advertisement

Notably, as was the case with the data-loss bug, a Windows Insider Preview tester had spotted the presence of ZIP file bug three months ago, and reported it to the Feedback Hub. However, thanks to just a few upvotes on the bug report (as was the case with the data-loss bug, ZDNet notes), it appears to have been overlooked by Microsoft when compiling the Windows 10 October 2018 Update. BleepingComputer adds that this bug was fixed in the Windows 10 Insider Preview Build 18234 (19H1) release that was pushed to testers a full month before the public rollout of the October 2018 Update. Unfortunately, this fix never made it to general users, but with a fix already in builds, one can expect Microsoft to patch it soon enough.

In light of the data-loss bug and how it was originally caught by testers but missed by Microsoft, the Redmond giant had published a short blog post on how it was changing the manner in which bugs could be reported in the Feedback Hub - bug reporters would now be able to add a severity rating. This, Microsoft hopes, would help ensure Windows 10 developers don't miss out severe reports when fixing bugs in public releases. "We believe this will allow us to better monitor the most impactful issues even when feedback volume is low," Brandon LeBlanc, Senior Program Manager on the Windows Insider Program Team said.

Advertisement

Next up, we have a new zero-day vulnerability reported by a security researcher who for now is just known by their Twitter handle - SandboxEscaper. It was publicly outed on Twitter on Tuesday, and this is not the first time that SandboxEscaper has found a zero-day Windows vulnerability and publicly outed it - the last time was less than two months ago. Microsoft acknowledged August's bug report in a statement to ZDNet, and a fix was rolled out in the September 2018 Patch Tuesday update, but not before PowerPool group used it in a malware distribution campaign.

Getting back to Tuesday's zero-day vulnerability disclosure by SandboxEscaper, a GitHub proof-of-concept has also been published alongside. The bug affects the Microsoft Data Sharing service, known as dssvc.dll in Windows 10, Windows Server 2016, and Windows Server 2019. The vulnerability allows attackers to elevate privileges on a machine they already have access to. While the proof-of-concept exploit only details how an attacker can delete files they don't have permission to, the exploit could be modified to let attackers perform more actions, ZDNet cites several security experts to say. While Microsoft has yet to comment on this latest bug report, such a public disclosure may once again give bad actors a chance to weaponise it into malware campaigns before Microsoft can patch it. A security company called 0patch has in the meanwhile released a micropatch for the vulnerability, which could be used by concerned users before an official fix is released.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Lava Bold 2 5G India Launch Teased; Company Teases Design Ahead of Debut
  2. Nubia Neo 5 GT Announced With 6,210mAh Battery: Check Price, Features
  3. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  4. Moto Watch Review: The Best Smartwatch Under Rs. 6,000 in 2026?
  5. Honor 600 Lite Launched With 6,520mAh Battery and This Dimensity Chipset
  6. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  7. Here's When the Xiaomi 17T Could Make Its Way to India
  8. Nothing Phone 4a, Phone 4a Pro Launched in India at This Price
  9. Infinix Note 60 Ultra With Pininfarina Design Launched at MWC 2026
  1. ISS Crew Prepares to Send Japan’s HTV-X1 Cargo Spacecraft Back to Earth After Four Months
  2. OpenAI’s Codex App Is Now Available on Windows, Can Be Downloaded via Microsoft Store
  3. OpenAI Teases GPT-5.4 AI Model Launch Just a Day After Releasing GPT-5.3 Instant
  4. Nothing Headphone (a) Launched With Adaptive ANC, Customisable Controls: Price, Specifications
  5. Granny OTT Release Date: When and Where to Watch the Village Mystery Thriller Online?
  6. Andhaka OTT Release: Where to Watch the Telugu Drama-Thriller Online?
  7. Pookie OTT Release: When and Where to Watch Vijay Antony’s Romantic Drama Online?
  8. WhatsApp Plus Paid Subscription Reportedly in Development With Additional Customisation Options, Up to 20 Pinned Chats
  9. Samsung Patent Hints at Potential Clamshell-Style Foldable With Two Cover Displays
  10. Google Introduces Gemini 3.1 Flash-Lite as Its Fastest and Most Cost-Efficient AI Model
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.