Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Microsoft > Security

December 14th, 2012, 06:47 GMT · By

Windows 8 Security Hole Allows Users to Reset Account Passwords in Minutes

SHARE:

Adjust text size:

The password can be changed using the built-in tools exclusively
Enlarge picture
Windows 8 was designed to be a much more secure operating system, so it bundles several new tools and improved features to make sure that it’s harder to break into than any other Windows version.

Sadly, it appears that Microsoft has forgotten to fix an important password reset hack that also works on Windows 8 predecessors, including Windows Vista and Windows 7.

Reboot.pro user Jamal Naji has found a way to reset the Windows 8 login password using only the built-in troubleshooting tools, so no third-party software is required.

While we won’t provide detailed instructions on how to do this, it’s worth mentioning that the entire password reset trick comes down to replacing the Ease of Access app (and its process called utilman.exe) with a copy of a Command Prompt executable file (cmd.exe) with full administrator privileges.

That would obviously grant anyone full access to a Windows 8 computer, so with a few more commands, the password could be changed in minutes.

Surprisingly, the same issue also works on a bunch of other Windows versions, including Windows 8’s predecessors, and it’s hard to find a reason why Microsoft has actually skipped patching it.

Paradoxically, a few days ago, Nick Psyhogeos, Microsoft vice president, said during a media briefing that Windows 8 is one of the most secure operating systems to date, so it’s harder than ever to break into such a software.

He admitted, however, that hackers are finding new ways to crack Windows and its software applications, but he emphasized that Windows 8 features improved security tools that should protect it in front of a new wave of attacks that usually targets Microsoft’s operating systems.

We’ve contacted the company for an official statement on this and we will update this story as soon as we get an answer.


6,887 hits · 3 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Download Microsoft News for Windows 8

The Windows 8 Store Is Bloated with Ugly Apps, Says Game Developer

Microsoft Rolls Out Commercials for the Holiday Season – Videos

2012: A Year of Microsoft Milestones in a Two-Minute Video

Microsoft Claims It’s Pretty Difficult to Crack Windows 8 [WSJ]

READER COMMENTS:


Comment #1 by: Adrien on 14 Dec 2012, 08:52 UTC reply to this comment

It's an old trick available with windows xp, vista, 7, server, etc..

Comment #1.1 by: phantomhell on 16 Dec 2012, 02:58 GMT

There's many crack tools in the wild to hack 8's activations. :)

Comment #1.2 by: WarOfTheNerd on 16 Dec 2012, 14:56 GMT

Boot access means root access. This is not a major security flaw. If you can overwrite system files, you've already won. Also, who said you can't just edit the SAM hive directly? Y'know, the easy way.

This is why domains and remote storage exist, so even if the local computer is modified, one still needs the right username/password to access the roaming profile and remote network drives (which are on a server kept under lock and key).

In other news:

* Passwords can be reset in Linux by editing /etc/shadow and /etc/passwd
* NEWSFLASH: Passwords can be bypassed altogether using LiveCDs
* Mac OS X compromised! Age old single-user mode leaves Macs vulnerable!

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM