Windows 10 security alert: Update now if you don't want your PC to crash
Windows x security alert: Update at present if you don't want your PC to crash
This Windows x update news isn't but good news. It's a reason to update your PC correct now. Without it, someone or something could hitting your computer with the Blue Screen of Death (BSoD if you're curt on words) only past getting you to endeavor to open a nonexistent binder.
This news comes from Bleeping Calculator, which notes that the February 2021 Patch Tuesday download (released on February nine) contains a fix to the bug that Microsoft is tracking nether the Common Vulnerabilities and Exposures (CVE) tag CVE-2021-24098.
- The all-time laptops, ranked
- Protect your PC with the best antivirus software
- Plus: Beware links to Discord'due south website — information technology could exist malware
Nosotros reported on the flaw and tested out the exploit when it was first discovered less than a month ago — and it's legit. We do not know if information technology'south been actively exploited "in the wild," but at present that information technology's beingness publicized, information technology's not time to expect and find out.
Dubbed 'Windows Console Driver Denial of Service Vulnerability" by Microsoft, the flaw has merely one upside: it requires user interaction — and cannot exist performed without your involvement.
Microsoft's documentation notes that the "web-based assault scenario" could run into a website used to deliver a filepath that exploits the flaw, so you lot'd simply need to have a way to become someone to open up the web page.
Unfortunately, as anyone who has been the victim of a phishing attack has experienced, it'due south not hard to get your average user to open a link.
Information technology could be sent in a breathlessly-worded email or text from their depository financial institution compelling them to fix something in their account, or something less dramatic, similar a bulletin promoting information about the Covid-19 vaccines or the third stimulus check.
Or it could be buried in a harmless-looking spider web page. Just clicking on a malicious link might crash your PC, although there probable wouldn't be any permanent damage.
Fix it now with a Windows ten update
The February 2021 Patch Tuesday update is available to users via ane of xx different updates, listed at the lesser of their CVE-2021-24098 folio here.
To update your machine, follow these elementary steps.
- Select the Start/Windows button from the bottom left corner.
- Select the settings/gear button to a higher place the power button.
- Select the Update and Security button.
- Tap or click Windows Update in the left menu.
- Tap or click Check for Updates if y'all don't see any bachelor.
- Your updates should begin downloading. Make sure your active projects are saved, and agree to restart once the updates are downloaded.
How the exploit works
This flaw is exploited by getting a user to try to open up the beneath directory:
\\.\globalroot\device\condrv\kernelconnect
That's a local directory, which means users practise non even need to download a file to take their organization crashed. Yes, web browsers don't only navigate the internet: they tin besides browse system files.
A flaw in how Windows 10 performed error checking pushes the user directly to a arrangement crash.
This flaw was discovered by researcher Jonas Lykkegaard, who explained it all in his Twitter feed. At the fourth dimension, Microsoft told Bleeping Reckoner that it "has a client commitment to investigate reported security issues and we will provide updates for impacted devices as before long as possible."
And at present that we've explained how it works, and why you should run Windows Update ASAP, we're going to go brand sure our systems are updated.
Source: https://www.tomsguide.com/news/update-windows-10-now-if-you-dont-want-your-pc-to-crash
Posted by: erbeprisperfes.blogspot.com
0 Response to "Windows 10 security alert: Update now if you don't want your PC to crash"
Post a Comment