Skip to main content
  1. Home
  2. Computing
  3. News

Now fixed, Cortana exploit allowed anyone to bypass the Windows 10 lock screen

Add as a preferred source on Google
Image used with permission by copyright holder

McAfee Labs reports that Microsoft fixed a problem with Cortana that allowed anyone to read sensitive information on the Windows 10 lock screen and bypass the screen altogether. At the core of the issue was the file indexing process used by Windows 10 and Cortana’s contextual menu for manually asking the virtual assistant questions. 

If enabled, Cortana can be present on the Windows 10 lock screen so that anyone can ask her questions, not just the owner of the locked device. Prior to the fix, if you activated Cortana verbally but instead began typing your query manually, a contextual menu appeared. The problem was that all displayed results stemmed from indexed files and applications. 

Recommended Videos

Windows 10 keeps an index of all files and installed applications used on your PC so you can easily search for those items. This system also includes a method to peek inside your files and index their content. You can see the list of indexed file types by heading to “Indexing Options” on the Control Panel and navigating to the File Types tab after clicking “Advanced.” You’ll see that many file types are marked as “Index Properties and File Contents.” 

That said, you could initiate Cortana and manually begin searching for documents. Thus, if you kept a list of passwords in a text file named “passwords,” Cortana would display that file and its current location on the locked Windows 10 PC. 

“If the match is driven by file name matching, then you will be presented with the full path of the file,” McAfee’s report states. “If the match is driven by the file content matching, then you may be presented with the content of the file itself. Keep in mind that the entire user folder structure is indexed, which includes the default location for most documents but also for mappings like OneDrive.” 

But the problem didn’t just revolve around hunting down stored passwords. If the search located any document, script, or text file, it would be loaded by the associated editor and presented once the device owner logged onto Windows 10. The same could be said when loading Calculator, Notepad, and other programs from the contextual menu. That means you could essentially run malware on the PC without unlocking it. 

The deal with running malware using Cortana is that you need to be personally associated with the target PC, such as accessing your boss’ laptop or a company workstation storing secrets. One method of attack required dropping an executable file or PowerShell script on the target PC through file sharing or a disguised email attachment. Thus, the boss could open the file, unknowingly drop malware onto his PC, and then you sneak into the office and launch the executable or script from the lock screen. 

But the problems didn’t stop there. Using a string of inputs and an inserted USB stick, the team managed to reset a locked PC’s password using a PowerShell script from Cortana’s contextual menu, thus gaining access to the entire PC. 

Microsoft fixed the Cortana exploit on Tuesday, June 13.

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
WhatsApp can now open and edit PDFs without making you download them first
Adobe Acrobat is adding built-in viewing and annotation tools for PDFs shared through WhatsApp on larger screens
Text, Person, Aircraft

Adobe is making PDF attachments much less annoying in WhatsApp. Its new Acrobat integration lets you open a PDF and mark it up without downloading the file or leaving the conversation.

The feature is available today through WhatsApp Web and the Windows app. The headline comes with an important caveat, though. This isn’t full PDF editing. You can review and annotate a document, but you can’t rewrite its original text or rearrange the layout.

Read more
Substack now lets you check if a post was written by AI
A new Pangram-powered scanner lets you check posts, notes, and replies for signs of AI writing.
Video playing on Substack.

Substack is giving readers a way to check whether the post they're reading was written by a human or by a chatbot. The company has partnered with AI-detection firm Pangram to introduce new tools that will let users scan posts, notes, and replies for AI-generated text. CEO Chris Best introduced the features in a post titled "Against Claudefishing," his term for content that leans on AI while presenting itself as human work.

How the scanning tool works

Read more
China’s AI talent shortage has tech giants recruiting teenagers
Forget campus recruiting, china's biggest tech firms are betting on teenage coders.
Artificial Intelligence

A 13-year-old boy in Hangzhou has already won national AI competitions and built a following of more than 136,000 people online, all while his dad tries to figure out how to guide him through a field that barely existed when he himself was growing up. That family's situation, first reported by Rest of World, says a lot about where China's tech industry is heading right now.

Companies used to wait for graduates to walk through the door. Now they're reaching further back, first to undergrads, and increasingly to teenagers, hoping to spot rare talent before anyone else gets to them.

Read more