Cortana vulnerability allows hackers to bypass Windows 10 passwords to install malware

Researches show that voice assist is a security risk

Cortana

Security researchers have discovered a flaw with Microsoft's Cortana voice assistant that could enable hackers to bypass the login screen in Windows 10 and infect a system with malware.

The Israeli researchers, Tal Be'ery and Amichai Shulman, found the vulnerability after finding out that Cortana is always on and responds to voice commands, even when a machine is locked.

According to reports by Motherboard, a hacker could plug in a USB stick with a network adapter into the computer, then tell Cortana to launch the computer's browser and go to an unencrypted URL (non-HTTP). This adaptor the intercepts this session to send the browser to a malicious website, downloading malware and infecting the system.

"We start with proximity because it gives us the initial foothold in [a] network. We can attach the computer to a network we control, and we use voice to force the locked machine into interacting in an insecure manner with our network," Shulman told the publication.

Hackers could also connect a targeted computer to a Wi-Fi network they control by simply clicking on a selected network with a mouse, even when the computer is locked.

Advertisement
Advertisement - Article continues below

"One of the things we saw was that even when a machine is locked, you can choose the network to which that machine is attached," said Shulman.

"We still have this bad habit of introducing new interfaces into machines without fully analyzing the security implications of it," said Be'ery. "Every new machine interface that we introduce creates new types of vehicles to carry an attack vector into your computer."

The researchers will present the findings in a presentation at the Kaspersky Analyst Security Summit in Cancun this week.

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Recommended

Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/mobile/mobile-phones/354273/pablo-escobars-brother-launches-budget-foldable-phone
Mobile Phones

Pablo Escobar's brother launches budget foldable phone

4 Dec 2019
Visit/network-internet/wifi-hotspots/354283/industrial-wi-fi-6-trial-reveals-blistering-speeds
wifi & hotspots

Industrial Wi-Fi 6 trial reveals blistering speeds

5 Dec 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019