Microsoft Foils USB Hack In Latest Windows Update

When a USB stick is connected to a PC the Windows operating system enumerates the device.  In simple terms, this means Windows will check to see what type of device was just connected, a HID device, Mass Storage Devicet etc, it will also check the speed of the device.

During the enumeration process some registry entries are made into the Windows registry…this is where a hacker could get into your system and take control.  This is the update Microsoft issues earlier this week to fix the security flaw.

Since the vulnerability is triggered during USB enumeration, no user intervention is required. In fact, the vulnerability can be triggered when the workstation is locked or when no user is logged in, making this an unauthenticated elevation of privilege for an attacker with casual physical access to the machine. Other software that enables low-level pass-through of USB device enumeration may open additional avenues of exploitation that do not require direct physical access to the system.

So be sure to update your PC with the update notification comes through – it’s in your best interest.

Full Microsoft article here:

Read More Articles

Keep exploring more stories, analysis, and technical insights.

usb-write-protect-switch-review-blog-image

Featured Product Review

Review: USB Write Protect Switch Verse USB Write Protect Controller

Review with pictures and video When it comes to making a USB stick read only, or USB write protected, there are two options. The first is...

Read the review