Open Sesame: Although Microsoft is reportedly trying to make it more secure Windows 10, υπάρχουν σφάλματα σε ορισμένα χαρακτηριστικά που καθιστούν τη ζωή των hackers πολύ εύκολη.
A new one called Open Sesame allows hackers to run malicious code on a Windows 10 PC using just their voice.
The bug exists in the Cortana digital assistant and was revealed by a team of researchers at the Black Hat conference in Las Vegas.
Researchers report that with this bug anyone could gain access to sensitive files, connect to malicious sites, download and execute infected files, and gain increased privileges (administrator level) on a locked computer.
All this can happen because the UI in Windows 10 allows apps to run in the background while the computer is locked. So without needing access to the device's mouse or keyboard, the digital assistant Cortana can run several processes.
Security researchers Amichai Shulman, Tal Be'ery of Kzen Networks, and Ron Marcovich and Yuval Ron of the Israel Institute of Technology discovered the flaw and reported it to Microsoft in April, according to a ThreatPost report (Black Hat 2018: Cortana Flaw Allowed Takeover of Locked Windows 10 Device).
The Open Sesame error has already been documented by the code name CVE-2018-8140 and Microsoft reports that no incidents of its exploitation have yet been uncovered exploit.
The flaw exists in Windows 10 Fall Creators Update (build 1709) and April 2018 Update (build 1803).
Open Sesame, What can you do? Updates are already running, so just let your system know.
_________________________________
- Passwords saved on your sleeve? and yet yes!
- US visa? social accounts, email, and phone numbers
- Facebook: best to apologize for permission
- Internet: Is decentralization possible? What does the blockchain do?