Windows Security Flaw Lets Hackers Install Malicious Apps: Report

Advertisement
By Ketan Pratap | Updated: 25 April 2016 17:27 IST
Highlights
  • Researcher used Regsvr32 to bypass AppLocker's whitelisting protections.
  • Microsoft is yet to comment on the flaw discovered in AppLocker.
  • The AppLocker protection feature was introduced in Windows 7.
Microsoft introduced the AppLocker feature in Windows 7, providing company administrators with the ability to whitelist and blacklist apps, ensuring that risk-laden apps are kept of the enterprise's networks. A researcher has however discovered a flaw in Windows AppLocker that lets hackers bypass the protection, and install any app they want.

Discovered by security researcher Casey Smith, the flaw allows hackers to use the Regsvr32.eve to install the app, by directing it to a hosted file or script. The app or script can then be installed, without administrator access or even modifying the registry - making it very difficult to reverse changes or monitor unauthorised use. The flaw, which could result in the PC installing malicious apps despite having Windows AppLocker, can be exploited in business editions of Windows 7 and higher.

"The amazing thing here is that regsvr32 is already proxy aware, uses TLS, follows redirects, etc...And.. You guessed a signed, default MS binary," wrote Smith while explaining the flaw in a blog post.

The Colorado-based Casey Smith also posted proof of concept scripts on GitHub to show the vulnerability.

Advertisement

Microsoft is yet to comment on the vulnerability and or release a patch for its Windows AppLocker. In the meanwhile, Eric Rand of Brown Hat Security (https://brownhatsecurity.com/mitigation-for-whitelisting-bypass-using-regsvr32-white-register.html ) has mitigation and suggests blocking Internet access of the Regsvr32.exe and Regsvr64.exe apps via Windows Firewall. He says, "There is at this time no patch available, but mitigation is possible via the Windows Firewall. Block %systemroot%\System32\regsvr32.exe and %systemroot%\SysWoW64\regsvr32.exe from network access and the largest threat surface will be mitigated."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Starlink Will Offer Unlimited Satellite Internet in India at This Price
  2. Jolla Phone Launched With 5,500mAh Replaceable Battery, Sailfish OS 5
  3. OnePlus 15R Roundup: Price in India, Specs and Everything We Know So Far
  4. Motorola Edge 70 With 5.99mm Slim Profile Will Launch in India on This Date
  5. Realme Narzo 90 Series 5G India Launch Announced
  6. Infinix Note 60, Note 60 Edge, Note 60 Pro Reportedly Spotted on SDPPI Website
  7. 'High' Risk Vulnerabilities Discovered in Google Chrome and Edge Browsers
  8. Gemini 3 Deep Think Model Is Now Available to These Users
  9. Sierra First Impressions: Tata's Icon Returns in Style
  10. Oppo Find X9 Is Now Available in India in This Colour Option
  1. Elon Musk Says Grok 4.20 AI Model Could Be Released in a Month
  2. Xiaomi 17 Global Variant Listed on Geekbench, Tipped to Launch in India by February 2026
  3. James Gunn's Superman to Release on JioHotstar on December 11: What You Need to Know
  4. The Boys Season 5 OTT Release Date: When and Where to Watch the Final Season Online?
  5. The Strangers Chapter 2 Now Available on Rent on Amazon Prime Video, Apple TV, and More
  6. Meta Acquires AI Wearables Startup Limitless, Could Expand Its Hardware Offerings
  7. Airtel Reportedly Partners With Google to Launch RCS Messaging for Users in India
  8. Jolla Phone Launched With 5,500mAh Replaceable Battery, Linux-Based Sailfish OS 5: Price, Availability, Features
  9. CERT-In Warns Chrome, Edge Users of ‘High’ Risk Vulnerabilities on Windows, macOS, and Linux
  10. Coinbase Reopens Registrations in India, Plans Fiat On-Ramp in 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.