A Vulnerability in Cortana, Now Patched, Allowed Attacker To Access a Locked Computer, Change Its Password (bleepingcomputer.com)
Catalin Cimpanu, reporting for BleepingComputer: Microsoft has patched a vulnerability in the Cortana smart assistant that could have allowed an attacker with access to a locked computer to use the smart assistant and access data on the device, execute malicious code, or even change the PC's password to access the device in its entirety. The issue was discovered by Cedric Cochin, Cyber Security Architect and Senior Principle Engineer at McAfee. Cochin privately reported the problems he discovered to Microsoft in April. The vulnerability is CVE-2018-8140, which Microsoft classified as an elevation of privilege, and patched yesterday during the company's monthly Patch Tuesday security updates. Further reading: Microsoft Explains How it Decides Whether a Vulnerability Will Be Patched Swiftly or Left For a Version Update.
He better have gotten a huge bug bounty for that. Remove code and auth changes via Cortana? That's gotta be worth at least the $10k PornHub paid for their PHP remote code execution (which wasn't even a PornHub bug, but a PHP one; so that company collected the PHP bounty on top of it as well).
How long before this bug is re-introduced?
It's continually blows my mind people *voluntarily* use Win10...the track record of show-stopping problems with this OS is well known.
So rise up, all ye lost ones, as one, we'll claw the clouds.
Far too integrated into the operating system for it's own good.
"Microsoft has patched a vulnerability in the Cortana smart assistant that ALLOWS an attacker with access to a locked computer to use the smart assistant and access data on the device, execute malicious code, or even change the PC's password to access the device in its entirety."
The patch was released 1 day ago. This vulnerability still exists for every Cortana-equipped computer that has not yet been updated.
And how many people refuse to update because updates have a history of breaking things?
Using Windows 7 again. After the disastrous 1803 update I decided to stop playing beta operating system tester.
Religion: The greatest weapon of mass destruction of all time
Welcome to Slashdot. The first post is always something about Donald Trump, "gay n*****s", apping apps for luddites, or, if you are very very lucky, something about Golden Girls and cosmonauts.
If you are very very unlucky, it's spam about a custom hosts file.