Cortana Software Could help anyone Unlock your Windows 10 Computer


Cortana, an artificial intelligence-based smart assistant that Microsoft has built into every version of Windows 10, could help attackers unlock your system password.

Source: thehackernews

With its latest patch Tuesday release, Microsoft has pushed an important update to address an easily exploitable vulnerability in Cortana that could allow hackers to break into a locked Windows 10 system and execute malicious commands with the user’s privileges.

In worst case scenario, hackers could also compromise the system completely if the user has elevated privileges on the targeted system.

The elevation of privilege vulnerability, tracked as CVE-2018-8140 and reported by McAfee security researchers, resides due to Cortana’s failure to adequately check command inputs, which eventually leads to code execution with elevated permissions.

“An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status,” Microsoft explains. “An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.”

Microsoft has classified the flaw as “important” because exploitation of this vulnerability requires an attacker to have physical or console access to the targeted system and the targeted system also needs to have Cortana enabled. More…

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

Blog at WordPress.com.

Up ↑

%d bloggers like this: