Windows Security Flaw Lets Hackers Install Malicious Apps: Report

Advertisement
By Ketan Pratap | Updated: 25 April 2016 17:27 IST
Highlights
  • Researcher used Regsvr32 to bypass AppLocker's whitelisting protections.
  • Microsoft is yet to comment on the flaw discovered in AppLocker.
  • The AppLocker protection feature was introduced in Windows 7.
Microsoft introduced the AppLocker feature in Windows 7, providing company administrators with the ability to whitelist and blacklist apps, ensuring that risk-laden apps are kept of the enterprise's networks. A researcher has however discovered a flaw in Windows AppLocker that lets hackers bypass the protection, and install any app they want.

Discovered by security researcher Casey Smith, the flaw allows hackers to use the Regsvr32.eve to install the app, by directing it to a hosted file or script. The app or script can then be installed, without administrator access or even modifying the registry - making it very difficult to reverse changes or monitor unauthorised use. The flaw, which could result in the PC installing malicious apps despite having Windows AppLocker, can be exploited in business editions of Windows 7 and higher.

"The amazing thing here is that regsvr32 is already proxy aware, uses TLS, follows redirects, etc...And.. You guessed a signed, default MS binary," wrote Smith while explaining the flaw in a blog post.

Advertisement

The Colorado-based Casey Smith also posted proof of concept scripts on GitHub to show the vulnerability.

Microsoft is yet to comment on the vulnerability and or release a patch for its Windows AppLocker. In the meanwhile, Eric Rand of Brown Hat Security (https://brownhatsecurity.com/mitigation-for-whitelisting-bypass-using-regsvr32-white-register.html ) has mitigation and suggests blocking Internet access of the Regsvr32.exe and Regsvr64.exe apps via Windows Firewall. He says, "There is at this time no patch available, but mitigation is possible via the Windows Firewall. Block %systemroot%\System32\regsvr32.exe and %systemroot%\SysWoW64\regsvr32.exe from network access and the largest threat surface will be mitigated."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  2. Redmi Turbo 5 Confirmed to Launch in India With This Rear Camera Setup
  3. Samsung Galaxy S26 FE Design, Key Charging Detail Surfaces via Database
  4. Samsung Galaxy A27 Spotted in Leaked Mint Colourway, Might Launch Soon
  5. Asus Dawn 7 Pro Series Launched With AMD Ryzen AI Chip, Two Display Options
  6. Infinix Hot 70 Pro India Launch Timeline, Key Specifications Leaked
  7. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  8. WhatsApp Users on iOS Are Finally Getting Access to This Useful Feature
  9. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  10. How to Watch WWDC 2026 Live on YouTube, Apple TV, and More
  1. Resident Evil Veronica Revealed at Summer Game Fest; Launch Set for 2027
  2. Microsoft Reportedly Working on Shared Audio Feature on Windows 11 Alongside Tweaked Widgets
  3. WhatsApp Multi-Account Support on iOS Reportedly Rolling Out to More Users
  4. HTX Delists USD1 Stablecoin, Asks World Liberty Financial to Reverse Freeze on Exchange's Addresses
  5. Asus Dawn 7 Pro Series Launched With Up to 16-Inch 144Hz Display, AMD Ryzen AI 7 445 Chip: Price, Features
  6. Redmi Turbo 5 Confirmed to Launch in India With Identical Dual Rear Camera Setup as Chinese Variant
  7. OnePlus Turbo 6X Series Launch Date Announced Along With Key Specifications, Features
  8. WWDC 2026: Tim Cook’s Final Apple Keynote Marks the End of an Era
  9. Infinix Smart 20 Launched in India With MediaTek Helio G81 Ultimate SoC, Slim 7.7mm Profile: Price, Features
  10. Infinix Hot 70 Pro India Launch Timeline Leaked; Could Feature Dimensity 7100 Chip, 6,000mAh Battery
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.