Windows Security Flaw Lets Hackers Install Malicious Apps: Report

Advertisement
By Ketan Pratap | Updated: 25 April 2016 17:27 IST
Highlights
  • Researcher used Regsvr32 to bypass AppLocker's whitelisting protections.
  • Microsoft is yet to comment on the flaw discovered in AppLocker.
  • The AppLocker protection feature was introduced in Windows 7.
Windows Security Flaw Lets Hackers Install Malicious Apps: Report
Microsoft introduced the AppLocker feature in Windows 7, providing company administrators with the ability to whitelist and blacklist apps, ensuring that risk-laden apps are kept of the enterprise's networks. A researcher has however discovered a flaw in Windows AppLocker that lets hackers bypass the protection, and install any app they want.

Discovered by security researcher Casey Smith, the flaw allows hackers to use the Regsvr32.eve to install the app, by directing it to a hosted file or script. The app or script can then be installed, without administrator access or even modifying the registry - making it very difficult to reverse changes or monitor unauthorised use. The flaw, which could result in the PC installing malicious apps despite having Windows AppLocker, can be exploited in business editions of Windows 7 and higher.

"The amazing thing here is that regsvr32 is already proxy aware, uses TLS, follows redirects, etc...And.. You guessed a signed, default MS binary," wrote Smith while explaining the flaw in a blog post.

The Colorado-based Casey Smith also posted proof of concept scripts on GitHub to show the vulnerability.

Microsoft is yet to comment on the vulnerability and or release a patch for its Windows AppLocker. In the meanwhile, Eric Rand of Brown Hat Security (https://brownhatsecurity.com/mitigation-for-whitelisting-bypass-using-regsvr32-white-register.html ) has mitigation and suggests blocking Internet access of the Regsvr32.exe and Regsvr64.exe apps via Windows Firewall. He says, "There is at this time no patch available, but mitigation is possible via the Windows Firewall. Block %systemroot%\System32\regsvr32.exe and %systemroot%\SysWoW64\regsvr32.exe from network access and the largest threat surface will be mitigated."

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Pro, iPhone 17 Pro Max Alleged Geekbench Listing Leaked
  2. Sony Announces Limited-Period Discount on Audio Products in India
  3. Nothing Phone 3 to Be Manufactured in India, Company Reveals Model Number
  4. OnePlus 13s Sale Starts Today in India: Check Price and Offers
  5. Realme 15 Pro Tipped to Launch in India in These Colour Options
  6. OnePlus 13 to Be Used for All BGMI Matches at BGMS 2025 Tournament
  7. OnePlus Nord 5 Allegedly Spotted on Geekbench With This Chipset
  1. Hubble Finds Cosmic Dust Coating Uranus’ Moons, Not Radiation Scars
  2. New Theory Challenges Black Hole Singularities, But Critics Raise Red Flags
  3. Solar Orbiter Captures First-Ever Close-Up of Sun’s South Pole, Revealing Magnetic Field Chaos
  4. The Summer I Turned Pretty Season 3 OTT Release Date: When and Where to Watch Final Season Online?
  5. Mokshapatam Hindi OTT Release: Where to Watch it Online?
  6. Titan: The OceanGate Disaster Now Streaming on Netflix: What You Need to Know
  7. Stellar Blade Becomes Sony's Biggest Single-Player Steam Launch Ever a Day After PC Release
  8. Microsoft 365 Copilot Vulnerable to Zero-Click EchoLeak Exploit, Cybersecurity Researchers Say
  9. Samsung Rolls Out One UI 8 Beta 2 Update for Galaxy S25 Series in Select Countries
  10. Amazon Prime Video Now Shows Twice As Much Ads As Before: Report
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.