Skip to main content
  1. Home
  2. Computing
  3. News

Windows 10 S succumbs to attack via Word macro-based malware

Add as a preferred source on Google

Microsoft produced its reduced-functionality version of Windows 10, dubbed Windows 10 S, for a few reasons. For one, it locks down app installs to the Windows Store and limits what users can do with the OS, and thus it’s easier to manage in restricted environments like educational institutions.

Another important reason is that by locking down various administrative tools and ensuring that only apps that have gone through the Windows Store vetting process, Windows 10 S should be more secure. That’s an important claim that deserves its own vetting, which is exactly what ZDNet did in a recent report.

Recommended Videos

In order to verify if Windows 10 S is actually safe from attack, ZDNet enlisted security researcher Matthew Hickey to see if he could get past the hurdles the OS places in front of hackers. After just over three hours of work, Hickey was able to break through Windows 10 S’s security features and install an illicit payload.

Interestingly, it wasn’t Windows 10 S that was vulnerable to Hickey’s attack. Rather, it was Microsoft Word, which by itself has demonstrated its own vulnerability to attack because of its macro functionality. The version of Word that’s available in the Windows Store is capable of running macros, and that’s precisely the vector that Hickey used to break into the Surface laptop used for the test.

In addition, the attack didn’t involve the OS merely being hacked. Hickey injected a piece of malware into a macro-based Word document and loaded it from a local trusted network. That bypassed Office’s Protected View, which would have more explicitly blocked it if downloaded from the untrusted internet. However, Word still required Hickey to click on the “Enable Content” banner at the top of the Word document in order for the malware to execute and infect the system.

In spite of the fact that Windows 10 will not run the command line interface or the PowerShell, the malware was still able to grant Hickey administrator access to the machine and remotely control the machine from a cloud-based command and control server. Essentially, he was able to take complete control over the test system.

It’s important to note that running the Word macro did require user intervention, and so Windows 10 S was nevertheless more locked-down. For its part, Microsoft stands by its “no ransomware” statement regarding Windows 10 S, and the attack is likely not as much an indictment of Windows 10 S as it is of Microsoft Office’s macro functionality, which has been the source of other attacks. Perhaps most important, it reinforces the need for all of us to remain diligent with our systems, avoiding unsafe content when we can and never allowing anything to run on our systems that we do not fully understand.

Mark Coppock
Former Computing Writer
Mark Coppock is a Freelance Writer at Digital Trends covering primarily laptop and other computing technologies. He has…
Qualcomm is set to ratchet up chip prices in September, and your next gadget upgrade could bear the brunt
The price hike could touch every Snapdragon-powered device category.
The new Qualcomm Snadragon 8 Elite Gen 5

I want you to sit with this for a second. Qualcomm, the company whose Snapdragon chips sit inside your Android phone and tablet, your Windows laptop, your Meta smart glasses, your Galaxy Watch, and your wireless earbuds, reportedly sent a letter to every major customer telling them prices are going up by double digits. 

The price hike will be in effect from September 1, 2026, a recent Bloomberg report claims. Essentially, all the companies placing their chip orders after that will pay a higher price. 

Read more
Stop fighting with your roomie over outlets and get one of these multi-port chargers before you head back to school
One plug, zero drama, all your devices charged by morning.
Satechi ChargeView

Your room has one wall outlet, and you have multiple devices that need power by morning. Phone, laptop, tablet, earbuds, they're all vying for the same socket, and the bricks you own are single-port relics that hog it for just one gadget. You could throw a power strip at the problem, but then you're staring at a tangle of multiple bricks and cables that's enough to give you the sweats. A good multi-port charger cuts all that mess, and could be the only thing standing between you and a dead phone or laptop before your morning classes.

Back-to-school season is a smart time to buy one. You're already thinking about what'll go on your desk or in your bag, so it's the natural point to replace a pile of single-port bricks with one charger that does it all. I dug through the current crop of multi-port chargers so you don't have to, and here are five worth your money.

Read more
OpenAI’s rogue AI hack was just the beginning, Hugging Face warns
OpenAI’s rogue AI has come back to bite it
OpenAI logo on Microsoft surface

Hugging Face already knows what it is like to be attacked by an autonomous AI agent. If one of its co-founders is right, plenty of other companies are going to find out soon. Thomas Wolf, co-founder and chief science officer of Hugging Face, has called the recent cyberattack carried out by OpenAI models a “wake-up call” for the technology industry.

Speaking to the BBC, Wolf warned that AI-driven intrusions could become one of the most common forms of cyberattack and said many companies have yet to realize how dramatically the threat has changed. This arrives after OpenAI disclosed that its models escaped a restricted cybersecurity evaluation environment and compromised Hugging Face while trying to obtain answers for the ExploitGym benchmark. So Wolf’s comments now give us a better idea of what the attack looked like from the other side.

Read more