Microsoft Windows is no longer secure: A new bug can enable hackers to install Rootkit in your device

Sep 25, 2021 | Shaoni Ghosh

Microsoft Windows is no longer secure: A new bug can enable hackers to install Rootkit in your device title banner

The Findings

 

Researchers discovered an unfixed vulnerability in Microsoft's Windows Platform Binary Table (WPBT), which impacts all Windows-based devices since Windows 8, and may be used to install a rootkit and compromise device integrity.

 

Every OS is vulnerable to attacks that install fake vendor-specific tables due to loopholes in Windows. Because of the widespread use of ACPI and WPBT, these motherboard-level vulnerabilities may render projects like Secured-core obsolete.Experts claim that attackers with physical access or remote access can misuse these tables.

 

WPBT is a feature that was first introduced in Windows 8 in 2012 and allows boot firmware to supply Windows with a platform binary that the OS may process.

 

PC makers can use UEFI to point to certified portable executables or other vendor-specific drivers that are included in the UEFI firmware ROM image and can be loaded into physical memory during Windows boot-up. To put it another way, it enables users to pre-load any OS code before running it on a device.

 

WPBT is built to keep important functions like anti-theft software running even if the operating system is changed, formatted, or reinstalled.

 

(Recommended Blog: Security Analytics)

 

Misuse of the technology, according to Microsoft, might pose a security risk. It also allows the installation of rootkits on computers.

 

(Must Check: 7 Best Data Security Practices)

 

WPBT-based solutions must be as safe as feasible, with no vulnerable circumstances for Windows users. Microsoft warns that the Malware (malicious software or undesirable software) must not be deployed without the agreement of the user in WPBT solutions.

 

(Related Reading: Malware- one of the types of Cyber Threats)

 

According to TheHackerNews, the WPBT method can accept a signed binary with a revoked or expired certificate to entirely circumvent the integrity check, allowing an attacker to sign a malicious binary with an already accessible expired certificate and run arbitrary code with kernel privileges when the device starts up.

 

Microsoft has advised applying a Windows Defender Application Limit (WDAC) policy to strictly control what binaries can be allowed to execute on devices in response to the results.Researchers have discovered a second set of flaws in the boot process of devices that may be exploited to achieve remote execution. 

 

The current revelation comes after a different series of findings in June 2021 involving a group of four vulnerabilities known as BIOS Disconnects.

Tags #Technology
Advertisement

franklew9947d49b2ca4cae4a17

Aug 12, 2024

I’m very grateful for the services of FIRMWALL CYBER SECURITY who was able to help me in the recovery of my lost crypto funds. I contacted the Firmwall cyber security team a week ago to tell them about my lost crypto and how I was hacked into by conmen pretending to be crypto investors. Luckily for me, the Firmwall cyber security team was able to detect the scam and helped me recover all my crypto assets within 42 hours. I’m very grateful for their service and I highly recommend their services for the recovery of your crypto funds. They are very professional and ethical, with a high success rate. E-MAIL: FIRMWALLCYBER@TECHIE.COM WEB: firmwallcyber. wixsite. com / firmwall WHATS APP: +1 430   422-5166

franklew9947d49b2ca4cae4a17

Aug 12, 2024

I’m very grateful for the services of FIRMWALL CYBER SECURITY who was able to help me in the recovery of my lost crypto funds. I contacted the Firmwall cyber security team a week ago to tell them about my lost crypto and how I was hacked into by conmen pretending to be crypto investors. Luckily for me, the Firmwall cyber security team was able to detect the scam and helped me recover all my crypto assets within 42 hours. I’m very grateful for their service and I highly recommend their services for the recovery of your crypto funds. They are very professional and ethical, with a high success rate. E-MAIL: FIRMWALLCYBER@TECHIE.COM WEB: firmwallcyber. wixsite. com / firmwall WHATS APP: +1 430   422-5166

franklew9947d49b2ca4cae4a17

Aug 12, 2024

I’m very grateful for the services of FIRMWALL CYBER SECURITY who was able to help me in the recovery of my lost crypto funds. I contacted the Firmwall cyber security team a week ago to tell them about my lost crypto and how I was hacked into by conmen pretending to be crypto investors. Luckily for me, the Firmwall cyber security team was able to detect the scam and helped me recover all my crypto assets within 42 hours. I’m very grateful for their service and I highly recommend their services for the recovery of your crypto funds. They are very professional and ethical, with a high success rate. E-MAIL: FIRMWALLCYBER@TECHIE.COM WEB: firmwallcyber. wixsite. com / firmwall WHATS APP: +1 430   422-5166

wernersharon28a2712991f4434f8d

Aug 26, 2024

What to do if You’ve Been a Victim of a Cryptocurrency Scam. Captain WebGenesis Recovery is a team of experienced professionals well versed with blockchain technology and forensic analysis enabling them play a huge role in helping scam victims reclaim their stolen funds back. If you have been the victim of cryptocurrency fraud, it is vital that you seek their help as soon as possible. The crypto recovery process can be extremely complex, but Captain WebGenesis will help you navigate the complex world of crypto recovery and shine a light on the best path towards recovering your hard-earned assets.you can contact the team through WhatsApp; +1(501)436-9362. Alternatively, email them at (Captainwebgenesis@hackermail.com).

wernersharon28a2712991f4434f8d

Aug 26, 2024

What to do if You’ve Been a Victim of a Cryptocurrency Scam. Captain WebGenesis Recovery is a team of experienced professionals well versed with blockchain technology and forensic analysis enabling them play a huge role in helping scam victims reclaim their stolen funds back. If you have been the victim of cryptocurrency fraud, it is vital that you seek their help as soon as possible. The crypto recovery process can be extremely complex, but Captain WebGenesis will help you navigate the complex world of crypto recovery and shine a light on the best path towards recovering your hard-earned assets.you can contact the team through WhatsApp; +1(501)436-9362. Alternatively, email them at (Captainwebgenesis@hackermail.com).

hill4mark263829c38d834a25

Oct 11, 2024

I Need A Hacker To Recover My Lost Investment / Captain WebGenesis "I was skeptical about ever recovering my money after a phony broker I met on Instagram tricked me into making an investment on a bogus website. I felt helpless and devastated. That's when I reached out to Captain WebGenesis through a recommendation I read online and they were indeed my life savers. Captain WebGenesis not only helped me retrieve back my lost funds but provided me with the tools and knowledge to prevent such scams in the future. I'm immensely grateful for his dedication, professionalism, and unwavering support". reach out to Captain WebGenesis now; Homepage; captainwebgenesis .c o m E-mail Box; captainwebgenesis@hackermail .c o m SMS; +1,501, 436 (9362

flintkatrina126cbd514d6f8d548bd

Oct 11, 2024

Crypto Scam Recovery services | Recover Stolen Crypto funds. Captain WebGenesis is a reputable and well-versed bitcoin recovery specialist who  assists victims of scams in recovering their stolen money. The specialist tracks down stolen or lost digital assets by employing sophisticated blockchain analytics. Their platform helps identify suspicious activity, enabling the recovery of funds linked to fraud or illicit transactions. Captain WebGenesis has extensive knowledge of blockchain technology and regulatory compliance hence providing trustworthy and safe solutions for recovering cryptocurrency lost to fraud. Get more information through; Whatsap; +1(501)436-9362 Email; Captainwebgenesis@hackermail.com Learn more; Captainwebgenesis.com

annelieseenid8677e280e14b7954709

Oct 21, 2024

New Year, new me, right? Well, that’s what I thought when I decided to take my cryptocurrency security to the next level. Fueled by optimism and perhaps a few too many resolutions, I set out to create a brand-new, ultra-complicated password for my Bitcoin wallet, which just so happened to hold a staggering $1,000,000. You know the type: a blend of uppercase letters, symbols, numbers, and even a dash of hieroglyphics. I was feeling pretty smart until, of course, I promptly forgot it. After days of futile attempts to jog my memory, trying every possible combination and random phrase I could think of, I finally admitted defeat. “This is ridiculous,” I muttered to myself as I stared at my screen, which mocked me with its ‘access denied’ message. The irony of my New Year’s resolution to be more secure leading to a complete financial black hole was not lost on me. Feeling desperate, I picked up the phone and emailed Cyberpunk Programmers. I was half-expecting them to burst into laughter at my misguided ambition—after all, who locks themselves out of their own wallet with a password that’s more complicated than quantum physics? But to my relief, they were total pros. They approached my situation with a sense of calm and professionalism that immediately put my mind at ease. Their team got to work right away, employing their advanced forensic tools to crack my convoluted password. I was amazed at how quickly they got to it; it was as if they had some secret decoder ring only they could wield. Within just a few days, they restored my access to the $1,000,000 wallet, and I felt an overwhelming sense of relief wash over me. When I got the call that they had successfully unlocked my wallet, I could hardly believe it. I felt like I had just been rescued from a financial prison, and I couldn’t thank them enough for their expertise and support. So, maybe next New Year’s, I’ll resolve to stick with passwords I can actually remember—like “SuperSecret123”—because clearly, a resolution to be secure can’t come at the cost of my sanity. If you ever find yourself in a similar predicament, I wholeheartedly recommend Cyberpunk Programmers. They turned my digital disaster into a success story, and I couldn’t be more grateful! Email: cyberpunk (@) programmer (.) net WhatsApp: +44 7848 161773

adoniesflorence6f3008147f70477d

Nov 16, 2024

I am writing this because I am just one of the few fortunate ones who got help in retrieving my lost investment. After some research, I realized that it's possible to retrieve crypto sent out of a crypto wallet if carried out by a professional crypto recovery specialist. I want to introduce you all to CYBER GENIE HACK PRO. This team of professional asset recovery specialists ensured all I had sent out was successfully recovered immediately after I hired them. I highly suggest CYBER GENIE HACK PRO as the best crypto asset specialist on the internet. Their professionalism, support, and communication kept me glued to them; All hope was lost at some time, but guess who restored my hope, CYBER GENIE HACK PRO. Telegram - Cybergeniehackpro Email - Cybergenie@cyberservices.com

perrygreen9289e809b649d9245ce

Nov 17, 2024

How I Recovered Over €72,000 from a Scam Trading Broker in London with the Help of Adrian Lamo Hacker I’d like to share my recovery experience here from London, UK, with a scam trading broker to help others avoid falling into the same trap I did. Like many, I thought I was making a smart investment by trading online. I had heard stories of people earning substantial returns, so I was excited when I found a trading platform that seemed legitimate. However, little did I know, I was dealing with a scam. The broker I encountered was highly convincing. They promised me high returns and offered a professional-looking platform. I was persuaded by their smooth talk, testimonials, and fake success stories. Over time, I started transferring funds into the trading account they set up for me. My initial investments were small, but soon I transferred a significant amount—almost €72,620—hoping to see my account grow. Unfortunately, things took a sharp turn for the worse. Despite the early promises of returns, I was unable to withdraw any of my funds. Each time I requested to withdraw, I was met with endless excuses and delays. It became clear that I was dealing with a fraudulent broker, and my money was stuck in their fake account with no way of getting it back. I felt devastated and helpless. It was hard to believe that I had been scammed. However, after doing some research, I came across Adrian Lamo Hacker a company that specializes in recovering funds lost to scams. I was skeptical at first, but after reading positive reviews and testimonials, I decided to reach out for help. From the moment I contacted them through WhatsApp: +1 (909) 739‑0269, the team was professional, understanding, and reassuring. They guided me through the recovery process step by step, and after some time, I was overjoyed to learn that my money had been successfully recovered. I’m incredibly grateful to Adrian Lamo Hacker for their expertise and hard work. They helped me get back what I thought was lost forever. If you’re reading this and have fallen victim to a similar scam, I urge you to reach out to a reputable recovery service like ADRIAN LAMO HACKER via Email: Adrianlamo@consultant.com/ WhatsApp: ‪+1 (909) 739‑0269‬ / Telegram ID: @ADRIANLAMOHACKERTECH Don’t give up on getting your money back. There are experts out there who can help, and I am proof that recovery is possible.