Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

Warning! 🚨 3 Critical Windows Vulnerabilities Found, Risking Remote Takeover and Malware Installation

Researchers have discovered three new vulnerabilities in the Windows operating system that allow attackers to bypass security systems, escalate privileges, and install malware, including a vulnerability in the Windows Hello authentication system.

Edited by SyncTech Solution Published Source Original source
Warning! 🚨 3 Critical Windows Vulnerabilities Found, Risking Remote Takeover and Malware Installation

πŸ“Œ Key Highlights:
- Researchers from the UK have discovered three new high-severity security vulnerabilities in Windows.
- The most concerning vulnerability is 'Download More RAM,' which can be used to escalate privileges to System Admin without direct machine access.
- The other two vulnerabilities affect Windows Hello authentication systems (facial and fingerprint scanning), which can be bypassed.

A team of researchers from the University of Birmingham and Durham University has unveiled the discovery of three new security vulnerabilities in the Windows operating system, presented at the USENIX Security Symposium. These vulnerabilities are severe enough to potentially allow malicious actors to bypass protection systems, gain System Administrator-level control of a machine, and install malware remotely.

πŸ‘Ύ Vulnerability One: 'Download More RAM'
This humorously named vulnerability has nothing to do with adding RAM. Instead, it is an attack technique that exploits a write protection flaw on certain motherboard components. This allows an attacker who can already run code on the machine to successfully escalate their privileges to the highest level (SYSTEM privileges), meaning they can take complete control of the machine.

πŸ“Έ Vulnerability Two: Bypassing Windows Hello Facial Recognition
Researchers found that Windows Hello's facial recognition system can be tricked using a simple technique: by projecting a low-resolution infrared (IR) image of the legitimate user through certain USB webcams, the machine can be successfully unlocked. This vulnerability has been tested and found to affect laptops from leading brands such as Dell, Lenovo, and even Microsoft itself.

πŸ‘† Vulnerability Three: Hacking Windows Hello Fingerprint
The final vulnerability concerns the fingerprint scanning system. Researchers were able to create what is called a 'Master Print' by intercepting and manipulating data from the fingerprint sensor. This Master Print can then be used to unlock machines that use the target's fingerprint, posing another significant concern for users relying on biometric authentication.

This discovery serves as a reminder for all Windows users, especially Windows 11 users, to prioritize regular security patch updates and closely follow news from Microsoft to protect themselves from potential cyber threats arising from these vulnerabilities.

πŸ’¬ Do you use Windows Hello to log in? Are you concerned about these vulnerabilities? Feel free to share your thoughts!

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.