Windows Security Flaw Lets Hackers Install Malicious Apps: Report

Advertisement
By Ketan Pratap | Updated: 25 April 2016 17:27 IST
Highlights
  • Researcher used Regsvr32 to bypass AppLocker's whitelisting protections.
  • Microsoft is yet to comment on the flaw discovered in AppLocker.
  • The AppLocker protection feature was introduced in Windows 7.
Microsoft introduced the AppLocker feature in Windows 7, providing company administrators with the ability to whitelist and blacklist apps, ensuring that risk-laden apps are kept of the enterprise's networks. A researcher has however discovered a flaw in Windows AppLocker that lets hackers bypass the protection, and install any app they want.

Discovered by security researcher Casey Smith, the flaw allows hackers to use the Regsvr32.eve to install the app, by directing it to a hosted file or script. The app or script can then be installed, without administrator access or even modifying the registry - making it very difficult to reverse changes or monitor unauthorised use. The flaw, which could result in the PC installing malicious apps despite having Windows AppLocker, can be exploited in business editions of Windows 7 and higher.

"The amazing thing here is that regsvr32 is already proxy aware, uses TLS, follows redirects, etc...And.. You guessed a signed, default MS binary," wrote Smith while explaining the flaw in a blog post.

The Colorado-based Casey Smith also posted proof of concept scripts on GitHub to show the vulnerability.

Advertisement

Microsoft is yet to comment on the vulnerability and or release a patch for its Windows AppLocker. In the meanwhile, Eric Rand of Brown Hat Security (https://brownhatsecurity.com/mitigation-for-whitelisting-bypass-using-regsvr32-white-register.html ) has mitigation and suggests blocking Internet access of the Regsvr32.exe and Regsvr64.exe apps via Windows Firewall. He says, "There is at this time no patch available, but mitigation is possible via the Windows Firewall. Block %systemroot%\System32\regsvr32.exe and %systemroot%\SysWoW64\regsvr32.exe from network access and the largest threat surface will be mitigated."

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  2. Nothing Phone 4a, Phone 4a Pro Launched in India at This Price
  3. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  4. Moto Watch Review: The Best Smartwatch Under Rs. 6,000 in 2026?
  5. Nothing Phone 4a vs Motorola Edge 70: Price in India, Features Compared
  6. Lava Bold 2 5G India Launch Teased; Company Teases Design Ahead of Debut
  7. You Can Now Use OpenAI's Codex App on Windows
  8. Nothing Launches Headphone (a) With Adaptive ANC, Spatial Audio Support
  9. Infinix Note 60 Ultra With Pininfarina Design Launched at MWC 2026
  10. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  1. Samsung Galaxy A37 5G and Galaxy A57 5G Specifications Reportedly Leaked in Full Ahead of Launch
  2. ISS Crew Prepares to Send Japan’s HTV-X1 Cargo Spacecraft Back to Earth After Four Months
  3. OpenAI’s Codex App Is Now Available on Windows, Can Be Downloaded via Microsoft Store
  4. OpenAI Teases GPT-5.4 AI Model Launch Just a Day After Releasing GPT-5.3 Instant
  5. Nothing Headphone (a) Launched With Adaptive ANC, Customisable Controls: Price, Specifications
  6. Granny OTT Release Date: When and Where to Watch the Village Mystery Thriller Online?
  7. Andhaka OTT Release: Where to Watch the Telugu Drama-Thriller Online?
  8. Pookie OTT Release: When and Where to Watch Vijay Antony’s Romantic Drama Online?
  9. WhatsApp Plus Paid Subscription Reportedly in Development With Additional Customisation Options, Up to 20 Pinned Chats
  10. Samsung Patent Hints at Potential Clamshell-Style Foldable With Two Cover Displays
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.