New Windows zero-day flaw could give hackers deep access to your PC — how to stay safe
Two different Windows flaws popped up this week. What connects them is that both could give bad actors system privileges.
Two significant Windows vulnerabilities have come to light this week, both capable of granting hackers access to your PC with system privileges, and neither has been patched yet. The first, dubbed ShieldBreak, is a zero-day flaw discovered by Nightmare Eclipse, a bug hunter with a contentious rivalry with Microsoft. This vulnerability can bypass the RoguePlanet patch and exploit Microsoft Defender when it runs a scan, potentially allowing attackers to gain system privileges.
To stay safe, one can disable Microsoft Defender, though this may not be foolproof. Another vulnerability, Plug and Pwn, was disclosed during DEF CON 34 by security researchers Alejandro Hernando and Borja Martinez. This flaw exploits how Windows identifies and connects USB devices, forcing the installation of software packages with exploitable components, potentially even without user interaction or physical hardware.
To mitigate this threat, one could enable the DisableCoInstallers registry value, which prevents driver packages from using co-installers during device installation. However, combining this with device installation restrictions, hardware-ID allow-lists, and turning off Plug and Play device redirection on RDP and VDI hosts could provide a more robust defense.
Written by urgent.news from Tom's Guide's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.