Important: hackers can attack Windows users using empty folders
Krympress reports:
Journalists of the XDA publication said that hackers can attack Windows users using a kind of harmless empty folders.
In early April, Windows users found in their computers an empty InetPub folder. Later, Microsoft said that it was created in the interests of the security of the operating system (OS) and asked not to remove it.
Security researcher Kevin Bomont told XDA that through this folder you can organize an attack on Windows users. Using the InetPub folder, the attacker can fulfill a certain request through the command of the Windows line and block the receipt of updates for the OS. In theory, hackers can attack the system users through this mysterious folder. Bomont said he spoke about the problem of Microsoft, but did not receive an answer.
The InetPub folder, which appeared on computers with the update of CVE-2025-21204, was declared Microsoft as an element of the operating system. However, the fact that this one can be used for attacks, if it cannot be filtered properly, raises important issues regarding the methods of protecting the OS, says Anton Nemkin, a member of the State Duma committee on information policy, information technology and communications, federal coordinator of the digital Russia party project.
Since it can become a vulnerable point for attackers, it is important that the company quickly responds to such threats, otherwise users can become victims of attacks through simple operational vulnerabilities— he added.
In addition, such situations demonstrate the importance of the relationship between security updates and information interaction between developers and users. Kevin Bomont’s comment that Microsoft did not respond to his warning is not surprising — the company quite often ignores messages from pentesters, and then understands the consequences, Nemkin emphasized.
In conditions of rapidly changing threats, you need to act immediately, especially when it comes to such significant components as security updates— added the deputy.
Do not forget that the use of folders, such as InetPub, for attacks through the Windows command line requires only certain actions or inattention from the user.
This once again recalls how important user awareness of potential threats is. In such situations, it is worth remembering that attention to details, such as strange and empty folders, can prevent many problems. At the moment, an undeservedly simple offer to “not delete” the folder from the computer leaves the space for possible threats— explained Nemkin.
Finally, the question is also how Microsoft will respond to this incident.
It is important that the company not only releases updates that will solve the problem, but also provide the public with detailed recommendations for actions. At this stage, this whole situation gives a clear understanding that even small changes in the operating system can have serious consequences for its safety, and users should always maintain vigilance— concluded the parliamentarian.
Source: press service of the State Duma deputy Anton Nemkina
Crimea news | Krympress: Latest news and main events
Comments are closed.