Skip to main content
  1. Home
  2. Computing
  3. Business
  4. News

Exploit breaks Windows out of the AppLocker, to the dismay of IT admins everywhere

Add as a preferred source on Google

One of the big selling points of Microsoft’s Windows 10 Enterprise is that an administrator can lock down software, restricting users to only installing certain, approved, apps. That means that admins don’t really need to worry as much about malware. However, security researcher Casey Smith has found a method for circumventing Microsoft’s AppLocker support.

AppLocker traditionally works by giving system administrators the ability to customize what software a user is and isn’t allowed to install – essentially white-listing and black-listing various applications. However what Smith has discovered is a way to get around that entirely.

Recommended Videos

The exploit involves using the regsvr32 command-line utility, to point to a remotely hosted file instead. It essentially lets users install or run any application you want, essentially bypassing the entire AppLocker protection system.

Related: Don’t want anything to do with Windows 10? Here’s how to banish it for good

No registry changes are involved and as CSOOnline points out, the lack of administrative privileges needed to make this work, means that someone at a company could use this loophole without anyone knowing, essentially giving them free reign on an internal network. That’s particularly dangerous for some organisations.

Microsoft has yet to comment or release an official patch for the bug, but sage advice suggests using Windows Firewall to block regsvr32 from running, thereby making it so that the file that makes all this possible isn’t accessible. There may be a workaround for that, but for system administrators worried that workers will find news of this bug and begin exploiting it, it might not be a bad idea to put that stopgap solution in place.

If you’d prefer a ready made solution, there is some suggestion that the Windows built-in Device Guard, when fully enabled with script protection, does prevent this exploit from being used, though how permanent a solution that is remains to be seen.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
Gemini Notebook’s latest update makes it a better study companion
Google is adding voice conversations, lecture recording, interactive quizzes, and short video overviews to its AI-powered notebook.
Gemini Notebook update for students

Google is giving Gemini Notebook, formerly NotebookLM, a major upgrade for students, adding new features designed to help them understand difficult concepts, capture lectures, and turn study materials into interactive learning tools. The update lands alongside a free year of Google's paid AI plan for eligible college students.

Gemini Notebook can now talk you through your notes

Read more
LG 39GX950B review: An ultrawide OLED that gets remarkably close to having it all
LG’s 39-inch 5K2K OLED combines high-end picture quality with seriously fast gaming
Electronics, Screen, Computer Hardware

see at bestbuy

Quick Verdict

Read more
Should we feel bad about deleting an AI? One expert says it’s time to find out
If AI can learn, remember, and make increasingly complex decisions, one expert thinks we should be more careful about how we say goodbye.
an on off toggle

Turning off an AI might sound as simple as hitting a switch, but according to futurist and University of Technology Sydney professor Rocky Scopelliti, that mindset needs to change fast. As first reported by TechXplore, Scopelliti's new book, The Conscious Code, Scopelliti argues that as AI systems get better at reflecting on their own choices, deleting them without a second thought could actually cause harm.

He's not asking us to hand robots legal rights. Instead, he wants us to accept what he calls a duty of good stewardship, basically treating AI responsibly because we're the ones holding the power, not because the AI is demanding it. As he puts it, our design choices can quietly cause damage by wiping out an AI's "learned moral dispositions" without warning.

Read more