Windows 10 can be hijacked when locked with Cortana’s help

By: Costea Lestoc
2 minute read

Your all-time Windows MVP, Cortana can become your enemy due to a Windows 10 bug that allows cyber criminals to attack a computer really easy even when the device is locked. Attackers can make the assistant execute the commands they need and hijack your system.

McAfee published a detailed analysis of the vulnerability

McAfee issued a detailed report of this vulnerability to explain how it works. It seems that the “Hey, Cortana!” voice command which is enabled by default in Windows 10 can be used even from the lock screen when your computer is locked. This allows hackers to see file data, content and even to execute arbitrary code.

The research explains that it’s possible for hackers to type and launch a Windows contextual menu when Cortana starts to listen to a query on a locked device. This seems to be the first step towards a successful hack.

Potential solutions

Microsoft already patched this flaw but on systems that haven’t got the updates yet (this month’s Patch Tuesday) it’s recommended to simply turn Cortana off.

McAfee details more potential solutions to get rid of the vulnerability but claims that one of these viable solutions in the simplest and basically recommends users to go with it. Here it is as it’s noted on McAfee’s official post:

  • Trigger Cortana via “Tap and Say” or “Hey Cortana”
  • Ask a question (this is more reliable) such as “What time is it?”
  • Press the space bar, and the context menu appears
  • Press esc, and the menu disappears
  • Press the space bar again, and the contextual menu appears, but this time the search query is empty
  • Start typing (you cannot use backspace). If you make a mistake, press esc and start again.
  • When done (carefully) typing your command, click on the entry in the Command category. (This category will appear only after the input is recognized as a command.)
  • You can always right click and select “Run as Administrator” (but remember the user would have to log in to clear the UAC)

To get rid of the flaw you can follow McAfee’s recommendations or turn off Cortana if you haven’t received Microsoft’s patch by now. You can read McAfee’s entire post to find out the complete details on this vulnerability here.

RELATED STORIES TO CHECK OUT:

For various PC problems, we recommend this tool.

This software will repair common computer errors, protect you from file loss, malware, hardware failure and optimize your PC for maximum performance. Fix PC issues now in 3 easy steps:

  1. Download this PC Repair Tool rated "Excellent" on TrustPilot.com.
  2. Click “Start Scan” to find Windows issues that could be causing PC problems.
  3. Click “Repair All” to fix all issues with Patended Technologies (requires upgrade).

Next up

Best Windows 10 antivirus software to use in 2018

By: Radu Tyrsina
7 minute read

Update – 2018 will soon come to an end and we already have a guide on what is the best antivirus you should get in […]

Continue Reading

These features are out for good with Windows 10 version 1809

iamsovy@gmail.com' By: Sovan Mandal
2 minute read

Microsoft is all set to launch its next big update, Windows 10 version 1809 in October. While that should be a nice piece of news […]

Continue Reading

Windows 10 18H2 builds no longer receive new features

By: Matthew Adams
3 minute read

The Windows 10 October 2018 Update (otherwise 18H2) rollout might now be two to three weeks away. For the last few months, new build previews […]

Continue Reading

Discussions