May 31, 2017 By Larry Loeb 2 min read

In the past, Microsoft had a problem with bugs affecting different versions of Windows. This kind of thing happened in the era of Windows 95/98, where the use of special filenames could crash the OS. All that was needed was to call for a certain file as an image source, and Windows promptly died.

That problem is back again: Microsoft has a Windows bug in versions older than 10, which could cause a crash necessitating a reboot of the affected system. This time, the special file name is $MFT — the name given to a special metadata files used by Windows’ NTFS file system. It is found in the root directory of each NTFS volume, but it is by design not available to other software.

Resurfacing a Classic Windows Bug

Softpedia explained that the problem occurs if $MFT is used as a directory name. While direct use of the $MFT file is blocked by Windows, pointing to it in this way is still possible.

Once accessed in this manner, Windows permanently locks the file. The system then causes any attempted program launch to fail, because it will just hang until the file system has been unlocked — something that never happens.

If such a file is given as an image source by a webpage or the like, some browsers, such as Google Chrome, will try to stop the request. But Internet Explorer has no such compunctions and passes the bad request. This will cause a crash or the blue screen of death until a reboot is performed. Microsoft has not yet announced how it intends to resolve the issue.

Microsoft’s Problems Grow

To be fair, Microsoft has had its hands full lately. The Malware Protection Engine used in Windows Defenders had some serious problems that were recently discovered by Google’s Project Zero team.

Bleeping Computer noted that of the eight bugs that were found, five are basic denial-of-service (DoS) flaws that can crash the Malware Protection Engine. Microsoft has released patches for these vulnerabilities that should propagate via auto update as version 1.1.13804.0.

Generally, users are used to dealing with external threats to their systems. It is disheartening when poor design causes internal flaws that others can exploit and are at the discretion of the software manufacturer to fix, but regular patching and adhering to best practices in the meantime can make a difference.

More from

What’s behind unchecked CVE proliferation, and what to do about it

4 min read - The volume of Common Vulnerabilities and Exposures (CVEs) has reached staggering levels, placing immense pressure on organizations' cyber defenses. According to SecurityScorecard, there were 29,000 vulnerabilities recorded in 2023, and by mid-2024, nearly 27,500 had already been identified.Meanwhile, Coalition's 2024 Cyber Threat Index forecasts that the total number of CVEs for 2024 will hit 34,888—a 25% increase compared to the previous year. This upward trend presents a significant challenge for organizations trying to manage vulnerabilities and mitigate potential exploits.What’s behind…

Quishing: A growing threat hiding in plain sight

4 min read - Our mobile devices go everywhere we go, and we can use them for almost anything. For businesses, the accessibility of mobile devices has also made it easier to create more interactive ways to introduce new products and services while improving user experiences across different industries. Quick-response (QR) codes are a good example of this in action and help mobile devices quickly navigate to web pages or install new software by simply scanning an image.However, legitimate organizations aren’t the only ones…

Cybersecurity Awareness Month: 5 new AI skills cyber pros need

4 min read - The rapid integration of artificial intelligence (AI) across industries, including cybersecurity, has sparked a sense of urgency among professionals. As organizations increasingly adopt AI tools to bolster security defenses, cyber professionals now face a pivotal question: What new skills do I need to stay relevant?October is Cybersecurity Awareness Month, which makes it the perfect time to address this pressing issue. With AI transforming threat detection, prevention and response, what better moment to explore the essential skills professionals might require?Whether you're…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today