Categories: HiveNightmareNasty

HiveNightmare is a nasty new Windows bug. Here’s how to protect yourself

A new bug called ‘HiveNightmare’ reportedly lets anyone with local or remote access to your PC take it over. This is a fairly new and serious flaw in the latest versions of Windows 10, as well as in Windows 11, which is still being tested in the Windows Insiders program.

Using malware, the hacker can gain complete access to your PC without needing an administrative password. The bug originates from an alleged change in the recent versions of Windows 10 and 11 that grants unauthorized users the privilege to access the Security Account Manager (SAM). The SAM is a database that contains both usernames and passwords for local accounts on the operating system.

Unauthorized users can access a backed-up version of the SAM in a shadow copy that Windows systems create. A shadow copy is a backup, hidden on the main drive, of a Windows system’s most important files. Your system creates a shadow copy each time it installs a system update or upgrade. So, malware that gets onto a PC via a dodgy-looking email, phishing software, or a malicious web link would be able to locate the SAM file in the shadow copy. Consequently, the user’s password hashes are easily accessible and a hacker will most probably be able to crack the hashes and take over the user’s PC.

Microsoft has already looked into the issue and has warned its users. The company provided a statement to Toms Guide, saying, “An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”

Microsoft promises future “mitigations and workarounds” as its investigation progresses.

Along with promising workarounds, the company has suggested a few ways to keep your PC safe right now. These ways include restricting access to the file directory to the SAM, or deleting your shadow copy of Windows. However, the second way could be a pain if you ever need to restore Windows.

Other preemptive measures that you can take include avoiding spammy emails, installing a reliable antivirus, and restricting physical access to your PC by people you don’t trust.

Editors’ Recommendations

Read More

News Bot

Share
Published by
News Bot

Recent Posts

Connected Energy Market Changing Strategies to Remain Competitive : GE Energy, Connected Energy, Elster Group GmbH, Siemens

Connected Energy Comprehensive Study by Type (Smart Grid, Smart Solar, Home Energy Management Systems, Digital…

2 hours ago

Wireless Charging Market 2021 Predictable to Witness Sustainable Evolution : Qualcomm Incorporated, Samsung, Sony

Wireless Charging Comprehensive Study by Type (Inductive Technology, RF Technology, Resonant Technology, Others), Application (Electric…

2 hours ago

Durable Juvenile Products Market to See Huge Growth by 2026: Britax, Newell Rubbermaid, Kolcraft Enterprises

Durable Juvenile Products Market Size, Status and Forecast 2021-2026Edison, NJ -- (SBWIRE) -- 07/20/2021 --…

2 hours ago

Blockchain in Insurance Sector Market Changing Strategies to Remain Competitive : Applied Blockchain, AWS, Microsoft, IBM

Blockchain In Insurance Sector Comprehensive Study by Application (GRC management, Death and claims management, Identity…

2 hours ago

Tokyo Olympics 2020: Australia rocked by alleged cocaine ban

Tokyo Olympics 2020: Australia rocked by alleged cocaine ban  New Zealand HeraldOlympics in 2021 spur frustration…

2 hours ago

Afghan refugee sues Australian government saying detention prevents him saving his family from Taliban

Afghan refugee sues Australian government saying detention prevents him saving his family from Taliban  The Guardian…

2 hours ago