Windows: Empty inetpub folder creates a new security problem
#1
Information 
Quote:When Microsoft released the April 2025 security updates for Windows, users from all over the world started to notice that Microsoft's update created an empty folder in the main drive called inetpub.

This led to confusion, as Microsoft was tight lipped initially about the presence of the folder. The official release notes did not include any information about it.

Shortly thereafter, Microsoft revealed that it created the folder on purpose to "increase protection". Users and administrators were encouraged to keep the folder and not tinker with it.

Background information: Microsoft created the folder as a direct response to CVE-2025–21204, which allows attackers to use symlinks to elevate privileges.
It turns out now that the creation of the folder may very well be used by cybercriminals for nefarious purposes.

Security researcher Kevin Beaumont shared information about the issue on Medium. Beaumont discovered that Microsoft's fix "introduced a denial of service vulnerability in the Windows servicing stack".

The details:
  • Regular users may abuse the issue to stop all Windows security updates.
  • It takes a single command to from a regular (non-elevated) prompt to abuse the issue.
All that is required is to create a new symbolic link between the inetpub folder and an application like notepad. Symbolic links do not require elevation, which means that attackers do not need to gain elevated access to a system to block future security updates on it.

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Bitdefender 27.0.51.260
Bitdefender 27.0.5...harlan4096 — 08:11
VeraCrypt 1.26.24
VeraCrypt 1.26.24 ...harlan4096 — 08:09
NTEL Arc Graphics 32.0.101.6874 driver
Highlights  Int...harlan4096 — 08:06
Latest VeraCrypt update blocks screensho...
The initial announ...harlan4096 — 08:05
Google Meet will fully replace Duo calli...
In mid-2022, Googl...harlan4096 — 08:04

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (47)BrantgoG
avatar (41)tapedDow
avatar (49)eapedDow
avatar (46)Carlosskake
avatar (48)rapedDow
avatar (43)Johnsonsyday
avatar (48)Groktus
avatar (40)efodo
avatar (38)Tedscolo
avatar (45)brakasig
avatar (44)JamesReshy
avatar (46)Francisemefe
avatar (39)leoniDup
avatar (38)Patrizaancem
avatar (50)smudloquask
avatar (45)benchJem
avatar (38)biobdam
avatar (41)zacforat
avatar (46)NemrokReks
avatar (49)Jasoncedia
avatar (37)Barrackleve
avatar (39)Julioagopy
avatar (49)aolaupitt2558
avatar (47)vadimTob
avatar (37)leannauu4
avatar (39)storoBox
avatar (47)kinotHeemn
avatar (38)Ceballos1976
avatar (50)nteriageda
avatar (39)efynu
avatar (31)horancos

[-]
Online Staff
There are no staff members currently online.

>