Skip to main content

Cortana flaw enables hackers to load malicious websites from the lock screen

Two independent Israeli researchers recently discovered that anyone with access to a Windows 10 PC could use Cortana and a USB-based network adapter to download and install malware even if the machine remained locked. This was accomplished using voice commands directed to Cortana, which could load up a malicious website in a browser without unlocking Windows. The PC could also be moved to a wireless network controlled by the hacker. 

The two researchers, Tal Be’ery and Amichai Shulman, presented their method in a session called, “The Voice of Esau: Hacking Enterprises Through Voice Interfaces” during the Kaspersky Analyst Security Summit in Cancun, Mexico, last week. Their attack relied on Cortana’s ability to keep the microphone active at all times to receive voice commands, especially PCs that aren’t restricted to a single user’s voice. The attack also required physical access to the target PC. 

In their scenario, a hacker could sit down in front of a locked Windows 10 PC and insert a network adapter into one of the USB slots. After that, the hacker could verbally tell Cortana to open the web browser and head to any specific HTTP-based address that doesn’t rely on a secure connection (HTTPS means the connection is encrypted). The inserted adapter receives the outgoing command but directs the web browser to a malicious website instead. 

The malicious destination is designed to download malware to the machine even though it’s still locked. After that, the PC is at the mercy of the hacker. As previously stated, a hacker with physical access to the Windows computer can switch to a wireless, malicious network through the USB adapter: just click on the destination using a mouse even though the PC remains locked. 

Windows 10 provides several settings regarding Cortana. For starters, device owners can toggle on or off the ability for the virtual assistant to respond to the “Hey Cortana” voice command. There is also a checkbox to prevent the device from sleeping when it’s plugged in so Cortana can respond to commands. Most importantly, there are two main settings for voice command acceptance: Let Cortana respond to anyone or lock Cortana to one specific voice. 

That is not all. There is a specific setting for the lock screen, enabling users to enable or disable voice commands while the PC remains locked. Windows 10 also provides a keyboard shortcut you can toggle to disable or enable Cortana commands after pressing the Windows logo key and the “C” key simultaneously.  

“We still have this bad habit of introducing new interfaces into machines without fully analyzing the security implications of it,” Be’ery said. “Every new machine interface that we introduce creates new types of vehicles to carry an attack vector into your computer.” 

Ultimately, Microsoft resolved the issue discovered by Be’ery and Shulman. Browser-based commands made to Cortana on the lock screen now go directly to Bing, the company’s search engine. But because Cortana responds to other commands, the duo is currently investigating how these commands can be used for malicious purposes as well. 

Editors' Recommendations

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
The 4 best Raspberry Pi alternatives in 2024
Inside a Raspberry Pi.

When it comes to powerful and reliable mini-computers, one of the most popular options is the Raspberry Pi. In fact, this particular PC gets most of the mini-CPU fanfare, but that doesn’t mean it’s the only small computer worth considering. If you’re thinking about investing in a bite-sized machine, we’ve put together this list of four mini PCs in direct competition with Raspberry Pi.

Read more
Best 2-in-1 laptop deals: Turn your laptop into a tablet for $349
Lenovo Yoga 9i 14 Gen 7 laptop sits on a small desk folded like a tent.

If you find that your traditional laptop isn't quite doing it for you in terms of workflow, then you might want to consider taking some of what the best tablets and the best laptops have and combining them together in the form of 2-in-1 laptops. These can offer a ton of versatility to your workflow, such as being able to use them in handheld mode for drawing or presenting, as well as the fact that most, if not all, are touch-enabled, so you don't even have to use a mouse if you don't want to.
There are, of course, a ton of great choices out there, but some of the best 2-in-1 laptops can get quite expensive, especially when you're buying them from some of the best laptop brands out there. That's why we've gone out and looked for our favorite 2-in-1 laptop deals to help save you some effort. We've pulled from HP laptop deals, Dell laptop deals, the classic 2-in-1 Surface Pro deals, and more. Check them out below.

Asus Chromebook Plus 2-in-1 -- $349, was $499

Read more
Best Acer laptop deals: From Chromebooks to gaming laptops
Acer Nitro V

If you're looking to pick up a new laptop, then you may want to consider the Acer lineup, especially considering it's one of the best laptop brands when it comes to budget-oriented computers. That even includes gaming laptops. Even better, you can find a lot of great deals on Acer's laptops, meaning that the already budget-friendly laptops become even cheaper, which is why we've gone out to find our favorite deals and list them for you below. That said, if you can't find what you're looking for below, be sure to check out some of these other great laptop deals as well, since there is some crossover between this list and our picks for the best Chromebook deals, 2-in-1 laptop deals and gaming laptop deals.
Aspire 1 -- $200, was $300
 

If you need something very basic just to get online and do some general productivity and day-to-day stuff, then the Acer Aspire 1 is a good budget option. It has a 15.6-inch screen with an FHD resolution, which is nice to see at this price point, and the screen bevels are actually relatively thin for a budget-oriented product. Of course, it does come with a lower-end Intel Celeron N4500 and only 4GB of RAM, which means Windows 11 is in the reduced S mode, but the lower spec does mean the price can stay really low too.

Read more