Slashdot Mirror


A Vulnerability in Cortana, Now Patched, Allowed Attacker To Access a Locked Computer, Change Its Password (bleepingcomputer.com)

Catalin Cimpanu, reporting for BleepingComputer: Microsoft has patched a vulnerability in the Cortana smart assistant that could have allowed an attacker with access to a locked computer to use the smart assistant and access data on the device, execute malicious code, or even change the PC's password to access the device in its entirety. The issue was discovered by Cedric Cochin, Cyber Security Architect and Senior Principle Engineer at McAfee. Cochin privately reported the problems he discovered to Microsoft in April. The vulnerability is CVE-2018-8140, which Microsoft classified as an elevation of privilege, and patched yesterday during the company's monthly Patch Tuesday security updates. Further reading: Microsoft Explains How it Decides Whether a Vulnerability Will Be Patched Swiftly or Left For a Version Update.

2 of 59 comments (clear)

  1. Re:So, given the pace of new features in Win10 by Anonymous Coward · · Score: 2, Funny

    Most modern software that is used in the business world requires Windows 10. The telepresence and collaboration features are world-class and provide a huge boost to productivity and TTM. We have competitors that struggle along with other solutions and we're constantly celebrating wins over them, on nearly every opportunity.

  2. Re:Like how Moscow Donald surrendered to North Kor by Anonymous Coward · · Score: 0, Funny

    Wherever you live... Head towards the nearest beach. When you get there, grab a hand full of sand and pack it up your Hellary.