Though every high-profile company must deal with the occasional security incident, several phones have been ringing through Microsoft's hallways over the past 48 hours. First, a leak released more than 30 terabytes of internal builds and the source code for some drivers that could enable specialized attacks. Second, the "super-secure" Windows 10 S fell to its knees in the face of a malicious Word macro in just over three hours. Ouch.

Part of Windows 10 Source Code Stolen and Windows 10 S Hacked
Windows 10 S

A Massive Leak of Windows Source Code

Microsoft's security record has always left much to be desired, despite its advances in recent years. Of course, not all attacks are the company's responsibility, a detail made evident after the WannaCry incident, but we still get the feeling that not enough effort is being made, and the situation becomes much more serious when internal failures arise. How many Windows builds have been leaked to the web? To be honest, we can't count them. Any doubt was cleared over the weekend when the BetaArchive portal received 32 terabytes of data packed with private images of the operating system and a piece of its source code.

Part of Windows 10 Source Code Stolen and Windows 10 S Hacked
Leaked source code, Windows 10 S hacked in a few hours... Microsoft needs to review its methods

Several of the images belong to Windows builds for servers and 64-bit editions compatible with the ARM architecture. They also include debugging symbols, which present much more detailed and in-depth information about code execution and its behavior. The leaked code is what is known as the Shared Source Kit, delivered mainly to third parties. The WiFi, USB, storage, and Plug and Play system stacks are there. This is code with very high privileges within the operating system, and any malicious element with the necessary skill could create an exploit. Finally, the last part of the leak includes multiple copies of the Windows 10 Mobile Adaptation Kit, which, as its name suggests, is a set of tools to adapt Windows 10 to mobile devices.

Part of Windows 10 Source Code Stolen and Windows 10 S Hacked
Once privileged access is gained in Windows 10 S, everything is in the attacker's hands

Windows 10 S Hacked in Three Hours

If that seems like little, Windows 10 S received its first major security blow. Microsoft stated in early June that no known variant of ransomware can work on that version, highlighting its resistance to infections like WannaCry. The folks at ZDNet contacted the security firm Hacker House to put that to the test, and the results were disappointing. In just over three hours, Windows 10 S gave up elevated privileged remote access, courtesy of a Word macro. The Protected View feature prevents the macro from executing, but if the document is loaded from a trusted location, Word offers to open the macro from a top bar, something very tempting to an unsuspecting user. Microsoft's position? It rejected the demonstration and said its previous statement still stands, though it added that "will continue to work with responsible researchers" to provide "the most secure experience" to its customers. (?)

Source:

ZDNet