Site icon WinCert

Microsoft is trying to fix a bug that easily corrupts NTFS file system

<p>A security researcher Jonas L has discovered an NTFS vulnerability that impacts Windows 8&sol;8&period;1 and many Windows 10 versions&period;<&sol;p>&NewLine;<p>Unfortunately&comma; this is a long-existing flaw that has not been fixed yet and it became exploitable starting with Windows 10 v1803 and continues to v20H2 which is the latest major Windows 10 release&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-4065" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2021&sol;01&sol;code-1689066&lowbar;640&period;jpg" alt&equals;"" width&equals;"640" height&equals;"426" &sol;><&sol;p>&NewLine;<p>Apparently&comma; even the unsupported Windows XP operating system is affected by this bug&comma; but Windows 7 is not&period;<&sol;p>&NewLine;<p>This vulnerability that corrupts the NTFS file system can be exploited with a single command&comma; shortcut in a ZIP archive&comma; or even by a malformed HTML file&period;<&sol;p>&NewLine;<p>A simple command that is executed with a privileged account or in an elevated CMD window corrupts an NTFS hard drive will result in a system restart prompting the user to repair the corrupted disk records&period;<&sol;p>&NewLine;<p><span style&equals;"color&colon; &num;ff0000&semi;">Please do not run this command on your devices that contain important data since you WILL damage the file system and even lose your data&period; Use this command at your own risk and only on a test system&period;<&sol;span><&sol;p>&NewLine;<p>Here&&num;8217&semi;s the command line that causes havoc on Windows NTFS volumes&colon;<&sol;p>&NewLine;<p><code>cd c&colon;&bsol;&colon;&dollar;i30&colon;&dollar;bitmap<&sol;code><&sol;p>&NewLine;<p>The key issue lies in the <strong>&dollar;i30<&sol;strong> which is an NTFS Index Attribute that containing a list of files and subfolders from NTFS directories&period;<&sol;p>&NewLine;<p>Once the above command has been executed you will receive the following Security and Maintenance notification&colon;<&sol;p>&NewLine;<p><strong>Restart to repair drive errors&period; Click to restart your PC&period;<&sol;strong><&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-4064" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2021&sol;01&sol;repair-disk-errors&period;png" alt&equals;"" width&equals;"311" height&equals;"124" &sol;><&sol;p>&NewLine;<p>Once the PC is rebooted Windows will start the CheckDisk app and will fix the file system&period;<&sol;p>&NewLine;<p>Apart from running this command in the command prompt&comma; this flaw can also be exploited by creating an Internet shortcut file &lpar;&period;url&rpar; with an icon location set to C&colon;&bsol;&colon;&dollar;i30&colon;&dollar;bitmap&period; Once the system tries to display this icon the system will instantly become corrupted&period;<&sol;p>&NewLine;<p>Another way is to use this &period;URL shortcut file in a ZIP archive&comma; ISO&comma; VHD or VHDX files&period; The corruption will start as soon as the user extracts the ZIP archive or mounts ISO&comma; VHD&comma; VHDX files&period;<&sol;p>&NewLine;<p>Some users reported that pasting the <strong>&&num;8216&semi;&colon;&dollar;i30&&num;8217&semi;<&sol;strong> string into the browser address also results in a corrupted file system&period;<&sol;p>&NewLine;<p>Currently&comma; there is no fix for this flaw and until Microsoft releases a fix&comma; please be extremely careful when using &period;ZIP&comma; ISO&comma; VHD or VHDX files from untrusted sources&period;<&sol;p>&NewLine;

Exit mobile version