Windows 10: Windows has an 8-year-old security issue that is exploited and known by Microsoft for some time

Discus and support Windows has an 8-year-old security issue that is exploited and known by Microsoft for some time in Windows 10 News to solve the problem; Microsoft is doing a commendable job when it comes to Windows security. Keeping billions of devices secure is no small feat. Sometimes, however, it... Discussion in 'Windows 10 News' started by GHacks, Mar 19, 2025.

  1. GHacks
    GHacks New Member

    Windows has an 8-year-old security issue that is exploited and known by Microsoft for some time


    Microsoft is doing a commendable job when it comes to Windows security. Keeping billions of devices secure is no small feat. Sometimes, however, it appears that someone at Microsoft is pushing the breaks regarding specific vulnerabilities.

    Take the following attack method as an example. It is a vulnerability in .lnk shortcuts that is exploited to trigger malware downloads. It was discovered by Trend Micro in 2024 and reported to Microsoft in September 2024.

    Security engineers at Trend Micro say that the issue has been exploited since at least 2017 and that it has found almost a 1,000 of these links in the wild already.

    These links contain megabytes of whitespace characters according to Trend Micro to fool antivirus and other security solutions. Attacks come from four countries only -- North Korea, China, Russia, and Iran -- according to the researchers. Trend Micro revealed that the vast majority of attacks come from state-sponsored attack crews and fall in the information theft and espionage category. Government were targeted the most, followed by the private and financial sector, think tanks, and telecommunications.

    The attackers download and install different malware payloads on successfully exploited systems. Among them notorious payloads and loaders such as Lumma Stealer or GuLoader.

    Microsoft has not acted on the provided information. Trend Micro says that it decided to go public with the information because of Microsoft's inactivity. The threat "poses a significant risk "to the confidentiality, integrity, and availability of data maintained by governments, critical infrastructure, and private organizations globally" according to the researchers.

    Microsoft classified the issue as low severity according to Trend Micro, indicating that the issue may not be patched in the "immediate future".

    In a comment to The Register, a Microsoft spokesperson encouraged customers to "exercise caution when downloading files from unknown sources".

    Shortcut files can be analyzed on local Windows systems. The problem with the disclosed vulnerability is that the link files are specifically crafted. This means that the user won't see the exploit when analyzing the link shortcut according to Trend Micro.

    Some security solutions may recognize these malicious shortcuts already, others may do so in the near future.

    Now You: what is your take on this? Should Microsoft develop a fix and release it? Feel free to leave a comment down below.

    Thank you for being a Ghacks reader. The post Windows has an 8-year-old security issue that is exploited and known by Microsoft for some time appeared first on gHacks Technology News.

    read more...
     
    GHacks, Mar 19, 2025
    #1
  2. newtekie1 Win User

    Windows 8 Secure Boot Feature: Not So Secure?

    • Linux
    • Linux
    • Linux
    • Linux
    • Oh and OSX
    Here is a statement from a Kernal Developer at Red Hat:

    I'm not sure this exploits the legacy BIOS but rather it exploits the legacy boot method on MBR drives, injecting a signed key before the OS boots, which you are correct in that it has nothing to do with Windows 8. And the simplest fix would just be to require boot drives use GPT when Secure Boot is enabled in UEFI.
     
    newtekie1, Mar 19, 2025
    #2
  3. Windows 8 Secure Boot Feature: Not So Secure?

    So Linux is switching to secure boot also? Or they have to because of UEFI?
     
    Damn_Smooth, Mar 19, 2025
    #3
  4. Brink Win User

    Windows has an 8-year-old security issue that is exploited and known by Microsoft for some time

    How Windows was exploited in 2014


    Read more:
     
    Brink, Mar 19, 2025
    #4
Thema:

Windows has an 8-year-old security issue that is exploited and known by Microsoft for some time

Loading...
  1. Windows has an 8-year-old security issue that is exploited and known by Microsoft for some time - Similar Threads - has old security

  2. Microsoft has some really nonsensical security.

    in Windows 10 Gaming
    Microsoft has some really nonsensical security.: I recently had to change my phone number because the phone company I was going through turned out to be thieves. So I didn't get a lot of notice and had to change my phone number unfortunately. So when I try to sign into my Microsoft account because I hadn't signed in for a...
  3. Microsoft has some really nonsensical security.

    in Windows 10 Software and Apps
    Microsoft has some really nonsensical security.: I recently had to change my phone number because the phone company I was going through turned out to be thieves. So I didn't get a lot of notice and had to change my phone number unfortunately. So when I try to sign into my Microsoft account because I hadn't signed in for a...
  4. Microsoft has some really nonsensical security.

    in AntiVirus, Firewalls and System Security
    Microsoft has some really nonsensical security.: I recently had to change my phone number because the phone company I was going through turned out to be thieves. So I didn't get a lot of notice and had to change my phone number unfortunately. So when I try to sign into my Microsoft account because I hadn't signed in for a...
  5. How do I tell Microsoft that I am not 8 years old? For some reason Microsoft thinks I am 8...

    in Windows 10 Gaming
    How do I tell Microsoft that I am not 8 years old? For some reason Microsoft thinks I am 8...: When I log into my online Microsoft account it has me as being 8 years old. I was born in 1961. That prevents me from getting Bing Chat to work....
  6. How do I tell Microsoft that I am not 8 years old? For some reason Microsoft thinks I am 8...

    in Windows 10 Software and Apps
    How do I tell Microsoft that I am not 8 years old? For some reason Microsoft thinks I am 8...: When I log into my online Microsoft account it has me as being 8 years old. I was born in 1961. That prevents me from getting Bing Chat to work....
  7. Time to Patch: Microsoft released security patch for actively exploited issue

    in Windows 10 News
    Time to Patch: Microsoft released security patch for actively exploited issue: Microsoft released security updates for Windows yesterday on the March 2023 Patch Day. Among the patched security updates, several of which are rated critical by Microsoft, is a security issue that is exploited actively in the wild. The issue was reported by Google's Threat...
  8. Windows Security Exploit Protection settings

    in AntiVirus, Firewalls and System Security
    Windows Security Exploit Protection settings: Dear all In Windows Security > App- and browser control > Exploit Protection > Program settings There is a list of .exe files and you can add more prorgrams 1. What are those .exe files on the list? What does this list do? 2. Under some of the .exe files, it says "1 detention...
  9. My first virus on my 8-year old laptop.

    in Windows 10 Ask Insider
    My first virus on my 8-year old laptop.: Question: I have a virus on my system and it's making my computer do weird things without me even touching it. I want to backup all my files/media onto my external storage in fear of them being corrupted by the virus (I don't even know if that's possible tbh). If I plug in my...
  10. Is this a known issue?

    in Windows 10 Updates and Activation
    Is this a known issue?: Hello, In another thread I indicated that my computer shows that the KB4056892 update failed. I was informed how to find out if it did indeed install, which it has. My question is will the error in View installed History will ever be correct, or are there any concerns other...