1 min read

Beware New Windows Vulnerability With Remote Search Window Access

You may not know the name Matthew Hickey, but you should thank him for a recent discovery that could save you a lot of grief.

Hickey is the co-founder of a company called Hacker House.  He recently discovered a flaw that could allow for the opening of a remote search window simply by opening a Word or RTF document.

This newly discovered zero-day vulnerability is about as serious as it gets.

Here’s how it works:

A specially crafted Word Document or RTF is created which, when launched, will automatically launch a “search-MS” command, which opens a Windows Search window.

This window lists executable files on a remote share and the share can be given any name the attacker desires such as “Critical Updates” and the like. That would naturally prompt an unsuspecting user to click the file name to run that file.

Naturally, clicking the file name wouldn’t do anything other than install malware, which is exactly what the hackers are trying to do.

Although not quite as dangerous as the MS-MSDT remote code execution security flaw, this one is still incredibly serious. Even worse, there is not currently a patch that will make your system safer.

The good news however, is that there are steps you can take to minimize your risks.

If you’re worried about this security flaw, here’s what you can do:

  • Run Command Prompt as Administrator.
  • To back up the registry key, execute the command “reg export HKEY_CLASSES_ROOTsearch-ms search-ms.reg”
  • Execute the command “reg delete HKEY_CLASSES_ROOTsearch-ms /f”

Kudos to the sharp eyes of Matthew Hickey for first spotting this flaw.  We can only hope when the next zero-day rears its head, researchers like Mr. Hickey will be there to help point them out and show us how to defeat them.

Used with permission from Article Aggregator

Your Law Firm's IT Infrastructure Is Either Ready for Advanced Legal Software…or It Isn't

Your Law Firm's IT Infrastructure Is Either Ready for Advanced Legal Software…or It Isn't

Most law firms don’t discover their IT infrastructure is inadequate until they’re already halfway through deploying a new legal platform and things...

Read the full blog
Your Legal Case Called. Your Tech Stack Needs Work.

Your Legal Case Called. Your Tech Stack Needs Work.

Managing complex litigation without the right tools is like trying to win a trial with a yellow legal pad and a prayer. It can be done...but why...

Read the full blog
Alert Channels That Actually Work When It Counts

Alert Channels That Actually Work When It Counts

An emergency alert is only useful if people actually receive it, notice it, and understand what to do next.

Read the full blog

1 min read

Microsoft Windows 7 And 8 OneDrive Support Is Ending

Are you a OneDrive user running Windows 7, Windows 8, or Windows 8.1? If so be aware that on January 1st, 2022 your OneDrive desktop application will...

Read the full blog

1 min read

Windows 11 Makes it Harder to Switch from Edge Browser

Analysts who have been following the development of Windows 11 generally have good things to say about the redesign of the interface. There is one...

Read the full blog

1 min read

Mobile Devices Connected to Windows Known as Phone Link

Microsoft recently announced that it was doing a bit of re-branding.

Read the full blog