Skip to main content

Microsoft acknowledges serious Windows security vulnerability

On Tuesday, Microsoft confirmed the existence of a vulnerability present in several versions of the Windows operating system. If exploited, the glitch could leave users’ computers open to being fully controlled by an outside attacker.

The exploit, first reported on December 15 at a security conference in South Korea, takes advantage of the way Windows’ graphics rendering engine processes certain thumbnail images. The booby-trapped images could be placed in an Office document, a website, or an e-mail.

“An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the logged-on user,” Microsoft said in a statement.  “An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”

If that sounds positively frightening, you may be comforted to hear that so far reports of the vulnerability seem to be strictly theoretical – there are no known reports of an attack taking place in the wild.

The two most recent versions of Windows — Windows 7 and Windows Server 2008 R2 — are reportedly not susceptible to the bug. Microsoft suggests that concerned users of other Windows versions mitigate risks of an attack by running as limited users, not as users will full administrative controls.

Microsoft says that it is currently investigating the bug and may address the problem in a future security update.

Editors' Recommendations

Aemon Malone
Former Digital Trends Contributor
There are two versions of Windows 11. Here’s how to decide between them
Windows 11 logo on a laptop.

If you’re ready to take the plunge and purchase an upgraded version of Windows, then the biggest question you have is “which one?” Both Windows 11 Pro and Windows 11 Home are powerful operating systems with robust feature sets at affordable prices.

To help you make an informed decision, we’ll walk you through a feature comparison along with the differences in security, power, and price.
Windows 11 Pro or Windows 11 Home?
Microsoft tries to introduce the intent behind the Windows 11 versions in the naming of the systems.

Read more
Windows is about to axe these three iconic apps
A top-down view of the Surface Laptop Go.

Microsoft's upcoming Windows 11 24H2 update will include many new features, including a controversial new app. But PCWorld reports that the following major Windows 11 24H2 updates will also remove three iconic apps you may currently use: WordPad, Cortana, and Tips.

Although each of these are being discontinued, there are some specific details for how Microsoft is rolling out the changes. This change affects Cortana in Windows as a standalone app, but it will remain within other applications, such as Microsoft Teams Display, Outlook Mobile, Teams Mobile, and Microsoft Teams Rooms. Of course, Microsoft's push into AI with a full-screen version of Copilot will take the place of Cortana. This update to Copilot treats it more as a proper app, not unlike the ChatGPT Mac app that was recently announced.

Read more
Microsoft is adding a controversial app to Windows 11
Microsoft Surface Laptop 2 sitting on a table.

A new Windows 11 build is rolling out in Microsoft's Beta channel, and it includes an app that's been caught up in some controversy. Build 22635.3646 includes the PC Manager app for devices in China by default. This app is already available through the Microsoft Store, but the update suggests the app might be part of Windows 11 more broadly soon.

PC Manager falls in the category of "system optimizers" along the lines of the  Razer Cortex Game Booster. It cleans out temporary files, frees memory that's not being used, and digs deep into your hard drive to clean out unused files. According to Microsoft, it can even "reduce ads and app pop-up interruptions." An system optimizer from Microsoft sounds great as an official release in Windows 11.

Read more