Monday, May 19, 2025
HomeComputer SecurityResearchers bypassed Windows 10 Lock Protection and Access Cortana Voice Commands that...

Researchers bypassed Windows 10 Lock Protection and Access Cortana Voice Commands that leads to Install Malware

Published on

SIEM as a Service

Follow Us on Google News

The researcher discovered a new flaw in Windows 10 lock Protection that allows attackers to access the Cortana Voice Commands in the locked system and visit a malicious website to install the malware.

Cortana is a virtual assistant created by Microsoft for Windows 10, Windows 10 Mobile, Windows Phone 8.1.Cortana can recognize natural voice without the requirement for keyboard input, and answer questions using information from the Bing search engine.

Cortana Voice-command systems help to avoid to type every command into a keyboard but this ease of use comes new ways for hackers to control of computers and smartphones.

- Advertisement - Google News

Researchers find this flaw in locked Windows 10 computer by abusing Cortana agent that responds to some voice commands even when computers are asleep and locked.

This future could be abused by the attacker and gaining the physical access to plug a USB with a network adapter into the computer, then verbally instruct Cortana.

Also Read: Powerful APT Malware “Slingshot” Performs Highly Sophisticated Cyber Attack to Compromise Router

Later the instruction which is given to the Cortana by attacker computer’s browser and go to a web address that does not use https.

An inserted adaptor will intercept the request and redirect it visit the malicious website and launch the malware.

“Default setting tells Cortana to respond to any voice calling “Hey Cortana,” even when the computer is locked. An alternate setting tries to limit this to just the computer owner by telling Cortana to “try to respond only to me.”

According to Motherboard, Once an attacker compromises a Cortana machine, per Be’ery and Shulman’s technique (Reserchers who finds this issue), and has this initial foothold, he or she can use the same concept to amplify the attack and move laterally to infect other computers in a room where that computer resides or on a local network

This would allow an attacker to download a malware through bypassing Windows 10 lock and install it too compromised computer to do an ARP poisoning method that tricks local machine to control by an attacker.

“The attack Be’ery and Shulman work because Cortana allowed direct browsing to websites, even when a machine was locked—or at least it did until Microsoft fixed the problem after the researchers disclosed it to the company.” Motherboard said.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Hackers Exploit RVTools to Deploy Bumblebee Malware on Windows Systems

A reliable VMware environment reporting tool, RVTools, was momentarily infiltrated earlier this week on...

Confluence Servers Under Attack: Hackers Leverage Vulnerability for RDP Access and Remote Code Execution

Threat actors exploited a known vulnerability, CVE-2023-22527, a template injection flaw in Atlassian Confluence...

New ModiLoader Malware Campaign Targets Windows PCs, Harvesting User Credentials

AhnLab Security Intelligence Center (ASEC) has recently uncovered a malicious campaign distributing ModiLoader (also...

Health Care Data Breach Costs BreachForums Admin $700,000 Fine

Conor Brian Fitzpatrick, the 22-year-old former administrator of cybercrime forum Breachforums, will forfeit approximately...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Exploit RVTools to Deploy Bumblebee Malware on Windows Systems

A reliable VMware environment reporting tool, RVTools, was momentarily infiltrated earlier this week on...

New ModiLoader Malware Campaign Targets Windows PCs, Harvesting User Credentials

AhnLab Security Intelligence Center (ASEC) has recently uncovered a malicious campaign distributing ModiLoader (also...

Printer Company Distributes Malicious Drivers Infected with XRed Malware

Procolored, a printer manufacturing company, has been found distributing software drivers infected with malicious...