New Security Warning After 1 Billion Windows Users Told Do Not Delete
Microsoft has issued a warning to its users after a highly respected security researcher discovered that a recent security update could block future security updates from being installed on their devices.
The update, which was meant to address a specific vulnerability in the Windows operating system, has sparked concerns among security experts and users alike. The issue lies with the 'inetpub' folder, which is part of the update. While Microsoft initially told users not to delete this folder under any circumstances, a recent investigation by Kevin Beaumont, a former Microsoft employee turned security researcher, revealed that deleting it could potentially stop all future Windows security updates from being installed.
Beaumont's findings have led him to warn that the update introduces a denial of service vulnerability in the Windows servicing stack. This allows non-admin users to stop all future security updates, leaving devices vulnerable to potential attacks.
The Windows Security Update Disaster Just Got Even Worse
Regular readers may recall Microsoft's previous security update fiasco, which inadvertently disabled the company's own Windows Hello security feature. Or, more recently, the April 8 update that installed a mysterious folder and sparked widespread concern among users.
Microsoft had to issue a notice explaining that the folder was critical protection against being attacked by threat actors exploiting a specific vulnerability. The company advised users not to delete this folder under any circumstances, emphasizing its importance in protecting against potential threats.
A Modest Warning from Microsoft
In response to Beaumont's findings, Microsoft has shared his report with the relevant Windows security team and stated that the case is currently rated as a Moderate severity issue. According to the company, the update fails to apply if the 'inetpub' folder is a junction to a file, but succeeds upon deleting the inetpub symlink and retrying.
Microsoft has assured users that it will consider implementing a potential fix for this issue. However, for now, the case remains closed, leaving many Windows users wondering what they can do to protect themselves from this potential vulnerability.
A Call to Action
As always, our advice is to update your operating system as soon as possible to ensure you have the latest security patches. While Microsoft has issued a warning about this particular issue, it's essential to remember that security updates are an ongoing process and should be taken seriously.
We urge all Windows users to take heed of this warning and keep their devices up-to-date with the latest security fixes. Stay vigilant and stay safe!