Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Windows 10 (and prior) bug corrupts your hard drive on seeing this file's icon (Zero-day, not fixed)
Bleeping Computer ^ | Jan 14, 2021 | Ax Sharma

Posted on 01/15/2021 8:43:27 AM PST by dayglored

An unpatched zero-day in Microsoft Windows 10 (and prior) allows attackers to corrupt an NTFS-formatted hard drive with a one-line command.

In multiple tests by BleepingComputer, this one-liner can be delivered hidden inside a Windows shortcut file, a ZIP archive, batch files, or various other vectors to trigger hard drive errors that corrupt the filesystem index instantly.

"Critically underestimated" NTFS vulnerability

In August 2020, October 2020, and finally this week, infosec researcher Jonas L drew attention to an NTFS vulnerability impacting Windows 10 that has not been fixed.

When exploited, this vulnerability can be triggered by a single-line command to instantly corrupt an NTFS-formatted hard drive, with Windows prompting the user to restart their computer to repair the corrupted disk records.

The researcher told BleepingComputer that the flaw became exploitable starting around Windows 10 build 1803, the Windows 10 April 2018 Update, and continues to work in the latest version.

What's worse is, the vulnerability can be triggered by standard and low privileged user accounts on Windows 10 systems.

A drive can become corrupted by merely trying to access the $i30 NTFS attribute on a folder in a certain way.

[Much more information, pics, examples, etc. at the article link...]

(Excerpt) Read more at bleepingcomputer.com ...


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: diskcorruption; internet; microsoft; tech; windows; windows10; windowspinglist; zeroday
Navigation: use the links below to view more comments.
first 1-2021-4041-44 next last
Looks like a problem to me, especially since it's not patched. Microsoft has been notified and says they're investigating. I expect more to emerge on this in coming days.
1 posted on 01/15/2021 8:43:27 AM PST by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; bajabaja; ...
Windows 10 (and prior) hard drive corruption vulnerability... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 01/15/2021 8:44:12 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored; ShadowAce; Swordmaker

Tech Ping!..........................


3 posted on 01/15/2021 8:44:40 AM PST by Red Badger (TREASON is the REASON for the SLEAZIN'.................................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; JosephW; Only1choice____Freedom; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; ...

Tech Ping


4 posted on 01/15/2021 8:46:17 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Welcome to Microsoft.


5 posted on 01/15/2021 8:47:13 AM PST by dinodino ( )
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
Looks like a problem to me, especially since it's not patched. Microsoft has been notified and says they're investigating. I expect more to emerge on this in coming days.

Once again, so glad I do not run Windows.

Linux Ubuntu19 5.10.0-051000-generic #202012132330 SMP Sun Dec 13 23:33:36 UTC 2020 x86_64 x86_64 x86_64 GNU/Linux

6 posted on 01/15/2021 8:48:17 AM PST by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Bkmk


7 posted on 01/15/2021 8:53:48 AM PST by sauropod ("No amount of evidence will ever persuade an idiot." - Mark Twain)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

.


8 posted on 01/15/2021 8:54:05 AM PST by QBFimi (It is not your responsibility to finish the work of perfecting the world... Tarfon)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

In before “It’s a feature not a bug” crowd.


9 posted on 01/15/2021 8:54:06 AM PST by BipolarBob (USA - Born July 4, 1776. Died Jan. 20, 2021 in the Year of our Covid.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: dayglored

Windows updated this morning. Maybe that’s the fix.


10 posted on 01/15/2021 8:58:03 AM PST by ArcadeQuarters (Socialism requires slavery.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

I glanced at the article and I didn’t see a solution to the vulnerability. It is easy to fix. Since, this occurs on NTFS volumes, change the security associated with the command prompt, cmd.exe, to only allow administrators to execute. I believe you can explicitly exclude access by non administrator account. This should be done to other utilities as well. Additionally, do not do every day work on an account administrator account. Sign on as Administrator when you do admin work, then sign off.


11 posted on 01/15/2021 9:03:21 AM PST by ConservativeInPA (See Profile: I'm giving up.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ArcadeQuarters
> Windows updated this morning. Maybe that’s the fix.

Unlikely -- I'd be astonished if Microsoft could get a fix out that quickly. More likely, it was the regular January Patch Tuesday update from Tue 1/12.

12 posted on 01/15/2021 9:04:46 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 10 | View Replies]

To: dayglored

See also:
Microsoft to fix Windows 10 bug that can corrupt a hard drive just by looking at an icon

A bizarre Windows bug for 2021
By Tom Warren @tomwarren Jan 15, 2021, 8:40am EST

https://www.theverge.com/2021/1/15/22232589/microsoft-ntfs-windows-10-bug-icon-file-flaw-vulnerability-comment


13 posted on 01/15/2021 9:04:55 AM PST by Wish2Post
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

This is why I won’t touch Win10; it is a virus.

Win7 is their last strong, user-friendly platform, so that’s what I’m running — including ‘downgrading’ a Win10 computer to Win7.


14 posted on 01/15/2021 9:06:03 AM PST by walford (https://www.facebook.com/wralford)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ConservativeInPA
I don't think so.... This is from the article:
What's worse is, the vulnerability can be triggered by standard and low privileged user accounts...
I haven't test it myself, of course...
15 posted on 01/15/2021 9:07:27 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 11 | View Replies]

To: walford
> This is why I won’t touch Win10; it is a virus. Win7 is their last strong, user-friendly platform, so that’s what I’m running — including ‘downgrading’ a Win10 computer to Win7.

The article has an update at the end saying that versions back to and including Windows XP have this same vulnerability. So Windows 7 almost certainly has the same problem.

16 posted on 01/15/2021 9:09:35 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 14 | View Replies]

To: dayglored
Maybe Gates should stick to fixing his dumpster fire of an OS


17 posted on 01/15/2021 9:24:00 AM PST by montag813 ("Fallen, fallen, is Babylon the Great")
[ Post Reply | Private Reply | To 1 | View Replies]

To: ConservativeInPA

“change the security associated with the command prompt, cmd.exe, to only allow administrators to execute.”

won’t work since Windows makes user accounts administrators by default ... almost no regular users have any idea how to make non-administrator accounts .


18 posted on 01/15/2021 9:32:33 AM PST by catnipman (Cat Nipman: Vote Republican in 2012 and only be called racist one more time!)
[ Post Reply | Private Reply | To 11 | View Replies]

To: dayglored

SO what is the one-line command and how do I know if my computer is in jeopardy?


19 posted on 01/15/2021 9:38:36 AM PST by nuconvert ( Warning: Accused of being a radical militarist. Approach with caution.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: montag813

... and leave the distribution of virii to the skilled professionals.


20 posted on 01/15/2021 9:38:59 AM PST by DuncanWaring (The Lord uses the good ones; the bad ones use the Lord.)
[ Post Reply | Private Reply | To 17 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-44 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson