Windows 10 WARNING - Hackers could take control of your PC unless you download THIS update

WINDOWS 10 users need to download a vital update after a Microsoft software vulnerability was discovered which lets hackers infect and take control of PCs.

Windows 10MICROSOFT

Windows 10 users have been put on alert about a Microsoft vulnerability was discovered

users have been put on alert about a Microsoft software vulnerability which hackers are using to infect PCs with malware and then take control of it.

The recently disclosed Microsoft Office vulnerability lets cybercriminals exploit a backdoor and deliver malware that can take control of PCs.

The CVE-2017-11882 vulnerability, which affects WordPad also, has existed for a staggering 17 years, according to cybersecurity website Security Week.

And recently hackers have been trying to exploit this to deploy the potent Cobalt malware through spam e-mails.

The e-mail contains an RTF document, and once opened users are greeted with a blank document alongside the message Enable Editing.

However, this message is only trying to cover what’s going in the background - as the malicious code gets downloaded and installed so the PC is hijacked.

The flaw has been categorised as security vulnerability CVE-2017-11882 and was fixed thanks to the updates provided on Microsoft’s November Patch Tuesday.

However, in the system requirements for all the patches available, it only mentions Windows operating systems as being supported.

Operating systems supported by the patches include Windows 10, Windows Vista, Windows 8, Windows 8.1 and Windows 7.

Outlining how the vulnerability works in a post, the Microsoft Security TechCenter said: “A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. 

“An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. 

“If the current user is logged on with administrative user rights, an attacker could take control of the affected system. 

“An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”

They added: “Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office or Microsoft WordPad software. 

“In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. 

“In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability. 

“An attacker would have no way to force users to visit the website. 

“Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file.”

Microsoft OfficeMICROSOFT

The vulnerability affects Microsoft Office and WordPad

The news comes after Windows fans were warned about the risks of not updating to the latest version of Microsoft’s flagship OS.

While Windows 10 is the most recent version of the Microsoft OS, it is not the most popular version for PC fans.

According to NetMarketShare, Windows 7 is used by more PC owners than Windows 10 - with the eight year-old OS having a market leading 46.63 per cent share.

This is compared to the second most popular PC OS, Windows 10, which has a 29.26 per cent chunk of the operating system market.

While Windows 8.1 and Windows XP have an operating system market share of 5.97 per cent and 6.47 per cent respectively.

However, for the huge amount of PC owners using an earlier version of Windows, they’ve been given a stark warning as to why they need to upgrade to Windows 10 as soon as possible.

The Register reported Microsoft has been patching out security bugs in Windows 10 but NOT immediately rolling those out to Windows 7 and 8 users.

This lag in updates leaves potentially hundreds of millions computers at risk of an attack.

The exploits that hackers and malware are taking advantage of is being fixed in the big Windows 10 releases.

However, this is only slowly filtering back to Windows 7 and 8 in the form of monthly software updates.

The news was revealed by researchers on Google’s Project Zero team.

Google Project Zero researcher Mateusz Jurczyk said: "Microsoft is known for introducing a number of structural security improvements and sometimes even ordinary bug fixes only to the most recent Windows platform.

"This creates a false sense of security for users of the older systems, and leaves them vulnerable to software flaws which can be detected merely by spotting subtle changes in the corresponding code in different versions of Windows."

Windows 10 WARNING - Hackers could take control of your PC unless you download THIS update

WINDOWS 10 users need to download a vital update after a Microsoft software vulnerability was discovered which lets hackers infect and take control of PCs.

Windows 10MICROSOFT

Windows 10 users have been put on alert about a Microsoft vulnerability was discovered

users have been put on alert about a Microsoft software vulnerability which hackers are using to infect PCs with malware and then take control of it.

The recently disclosed Microsoft Office vulnerability lets cybercriminals exploit a backdoor and deliver malware that can take control of PCs.

The CVE-2017-11882 vulnerability, which affects WordPad also, has existed for a staggering 17 years, according to cybersecurity website Security Week.

And recently hackers have been trying to exploit this to deploy the potent Cobalt malware through spam e-mails.

The e-mail contains an RTF document, and once opened users are greeted with a blank document alongside the message Enable Editing.

However, this message is only trying to cover what’s going in the background - as the malicious code gets downloaded and installed so the PC is hijacked.

The flaw has been categorised as security vulnerability CVE-2017-11882 and was fixed thanks to the updates provided on Microsoft’s November Patch Tuesday.

However, in the system requirements for all the patches available, it only mentions Windows operating systems as being supported.

Operating systems supported by the patches include Windows 10, Windows Vista, Windows 8, Windows 8.1 and Windows 7.

Outlining how the vulnerability works in a post, the Microsoft Security TechCenter said: “A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. 

“An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. 

“If the current user is logged on with administrative user rights, an attacker could take control of the affected system. 

“An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”

They added: “Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office or Microsoft WordPad software. 

“In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. 

“In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability. 

“An attacker would have no way to force users to visit the website. 

“Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file.”

Microsoft OfficeMICROSOFT

The vulnerability affects Microsoft Office and WordPad

The news comes after Windows fans were warned about the risks of not updating to the latest version of Microsoft’s flagship OS.

While Windows 10 is the most recent version of the Microsoft OS, it is not the most popular version for PC fans.

According to NetMarketShare, Windows 7 is used by more PC owners than Windows 10 - with the eight year-old OS having a market leading 46.63 per cent share.

This is compared to the second most popular PC OS, Windows 10, which has a 29.26 per cent chunk of the operating system market.

While Windows 8.1 and Windows XP have an operating system market share of 5.97 per cent and 6.47 per cent respectively.

However, for the huge amount of PC owners using an earlier version of Windows, they’ve been given a stark warning as to why they need to upgrade to Windows 10 as soon as possible.

The Register reported Microsoft has been patching out security bugs in Windows 10 but NOT immediately rolling those out to Windows 7 and 8 users.

This lag in updates leaves potentially hundreds of millions computers at risk of an attack.

The exploits that hackers and malware are taking advantage of is being fixed in the big Windows 10 releases.

However, this is only slowly filtering back to Windows 7 and 8 in the form of monthly software updates.

The news was revealed by researchers on Google’s Project Zero team.

Google Project Zero researcher Mateusz Jurczyk said: "Microsoft is known for introducing a number of structural security improvements and sometimes even ordinary bug fixes only to the most recent Windows platform.

"This creates a false sense of security for users of the older systems, and leaves them vulnerable to software flaws which can be detected merely by spotting subtle changes in the corresponding code in different versions of Windows."

Windows 10 WARNING - Hackers could take control of your PC unless you download THIS update

WINDOWS 10 users need to download a vital update after a Microsoft software vulnerability was discovered which lets hackers infect and take control of PCs.

Windows 10MICROSOFT

Windows 10 users have been put on alert about a Microsoft vulnerability was discovered

users have been put on alert about a Microsoft software vulnerability which hackers are using to infect PCs with malware and then take control of it.

The recently disclosed Microsoft Office vulnerability lets cybercriminals exploit a backdoor and deliver malware that can take control of PCs.

The CVE-2017-11882 vulnerability, which affects WordPad also, has existed for a staggering 17 years, according to cybersecurity website Security Week.

And recently hackers have been trying to exploit this to deploy the potent Cobalt malware through spam e-mails.

The e-mail contains an RTF document, and once opened users are greeted with a blank document alongside the message Enable Editing.

However, this message is only trying to cover what’s going in the background - as the malicious code gets downloaded and installed so the PC is hijacked.

The flaw has been categorised as security vulnerability CVE-2017-11882 and was fixed thanks to the updates provided on Microsoft’s November Patch Tuesday.

However, in the system requirements for all the patches available, it only mentions Windows operating systems as being supported.

Operating systems supported by the patches include Windows 10, Windows Vista, Windows 8, Windows 8.1 and Windows 7.

Outlining how the vulnerability works in a post, the Microsoft Security TechCenter said: “A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. 

“An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. 

“If the current user is logged on with administrative user rights, an attacker could take control of the affected system. 

“An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”

They added: “Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office or Microsoft WordPad software. 

“In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. 

“In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability. 

“An attacker would have no way to force users to visit the website. 

“Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file.”

Microsoft OfficeMICROSOFT

The vulnerability affects Microsoft Office and WordPad

The news comes after Windows fans were warned about the risks of not updating to the latest version of Microsoft’s flagship OS.

While Windows 10 is the most recent version of the Microsoft OS, it is not the most popular version for PC fans.

According to NetMarketShare, Windows 7 is used by more PC owners than Windows 10 - with the eight year-old OS having a market leading 46.63 per cent share.

This is compared to the second most popular PC OS, Windows 10, which has a 29.26 per cent chunk of the operating system market.

While Windows 8.1 and Windows XP have an operating system market share of 5.97 per cent and 6.47 per cent respectively.

However, for the huge amount of PC owners using an earlier version of Windows, they’ve been given a stark warning as to why they need to upgrade to Windows 10 as soon as possible.

The Register reported Microsoft has been patching out security bugs in Windows 10 but NOT immediately rolling those out to Windows 7 and 8 users.

This lag in updates leaves potentially hundreds of millions computers at risk of an attack.

The exploits that hackers and malware are taking advantage of is being fixed in the big Windows 10 releases.

However, this is only slowly filtering back to Windows 7 and 8 in the form of monthly software updates.

The news was revealed by researchers on Google’s Project Zero team.

Google Project Zero researcher Mateusz Jurczyk said: "Microsoft is known for introducing a number of structural security improvements and sometimes even ordinary bug fixes only to the most recent Windows platform.

"This creates a false sense of security for users of the older systems, and leaves them vulnerable to software flaws which can be detected merely by spotting subtle changes in the corresponding code in different versions of Windows."

Windows 10 - How to download for FREE before the end of the year
Windows 10 UPDATE - Microsoft reveals specs for 'highly secure’ PC Windows 10
Strictly Come Dancing 2017 Alexandra Burke HITS OUT critics bottom two musicals week BBC

Strictly Come Dancing 2017: Alexandra Burke HITS OUT at critics after bottom two shock

royal bank of scotland close branches jobs cuts

Royal Bank of Scotland to close 62 branches and axe 700 jobs in shake-up

Bali volcano Agung Bali news Bali Indonesia Bali update Bali volcano alert live webcam

Bali volcano WATCH LIVE: Locals brace for Mount Agung violent eruption - LIVE WEBCAM

Im A Celebrity 2017 Ant McPartlin Declan Donnelly ITV slam accusations racial slur

I'm A Celebrity 2017: ITV slam accusations of Ant McPartlin using 'racial slur'

Bali volcano Mount Agung news update flight empty Jetstar tourists stranded

Bali volcano: Shocking footage shows rescue flight half EMPTY as thousands remain stranded

Apple iPhone 7 Samsung Galaxy S8 best price offer deals

Samsung Galaxy S8 v iPhone 7 PRICE CRASH but which really is the cheapest smartphone?

Google Chrome update Incognito mode internet browser

Google Chrome SHOCK - Incognito mode will NOT stop your boss finding out what you searched

WhatsApp Update iOS Android Restricted Groups

WhatsApp update may let you REJECT and SILENCE people in a group chat

iPhone Users Google £500 Lawsuit

Own an iPhone? Google might be forced to pay you £500, and this is why

Galaxy S9 Samsung Galaxy S8 fingerprint sensor release date price

Bad news Galaxy S9 fans, this long-awaited feature may SKIP Samsung’s next phone

Wales South Africa live stream rugby How to watch online autumn internationals

Wales vs South Africa live stream - How to watch FINAL autumn international online

Apple macOS High Sierra 10.13.1 File Sharing Bug How To Fix

Apple's emergency fix for MacBook SECURITY FLAW includes fresh macOS High Sierra bug

iPhone iOS AutoCorrect Swear Words

How to stop your Apple iPhone autocorrecting EVERY swear word

Firefox Quantum Have I Been Pwned Data Breach

If you’re worried about being hacked, it could be time to drop Google Chrome

Google Maps iOS iPhone X Update

Google Maps gets a blockbuster update, but you’ll need THIS iPhone to actually notice

Samsung Galaxy Note 8 Microsoft Edition

It's no Surface Phone, but Microsoft now sells the Samsung Galaxy Note 8

Apple Pay Apple Store World AIDS Day Candy Crush

Apple Pay and App Store updated for World AIDS Day: How to donate when you make a payment

Kodi illegal streams warning add on block

Kodi shock news WON'T please users as add-on crackdown continues

Apple iPhone X best deal offer price

iPhone X offer finally makes this Apple flagship seem a lot more affordable

Samsung Galaxy S9 Release Date UK

Samsung Galaxy S9 release date LEAKS - and it’s closer than anyone thought

Samsung Galaxy X Release Date iPhone Apple Patent

Samsung Galaxy X’s most incredible new feature could be coming to iPhone

EE's hawk budget iPhone price release Apple

EE launches iPhone lookalike and it offers big features on a small budget

AOL Mail Login Not Working Internet Down

AOL is DOWN AGAIN: Mail and internet service NOT WORKING for hundreds of users

The Grand Tour season 2 watch online stream Amazon release date

The Grand Tour season 2 - Devices you need to stream and watch online

  • Find us on Facebook
  • Follow us on Twitter
  • Check us on Google+
  • Subscribe to our rss feed