Major security flaw on Windows 10 PCs revealed

29 November 2016

A serious security flaw discovered in Windows 10 allows non-administrative users to gain system-level access during upgrades of certain versions of the operating system.

The flaw was first discovered several months ago by white-hat Sami Laiho who held off on making the news public so that Microsoft could address the issue.

As Laiho describes:

“The installation of a new build is done by reimaging the machine and the image installed by a small version of Windows called Windows PE (Preinstallation Environment).”

“This has a feature for troubleshooting that allows you to press SHIFT+F10 to get a Command Prompt. This sadly allows for access to the hard disk as during the upgrade Microsoft disables BitLocker.”

There are currently no know fixes to the issue although Laiho does provide the following:

  • Don’t allow unattended upgrades.
  • Keep very tight watch on the Insiders (builds).
  • Stick to LTSB version of Windows 10 for now.

Now read: 5 secret tips to boost your gaming performance in Windows 10

You have read 2 out of 5 free articles. Log in or register for unlimited access.

Read now

The best gaming website in South Africa
MyGaming proudly displays the “FAIR” stamp of the Press Council of South Africa, indicating our commitment to adhere to the Code of Ethics for Print and online media which prescribes that our reportage is truthful, accurate and fair. Should you wish to lodge a complaint about our news coverage, please lodge a complaint on the Press Council’s website, www.presscouncil.org.za or email the complaint to [email protected] Contact the Press Council on 011 4843612.