Windows 10 disaster: bugs corrupting drives and crashing the system

Windows 10 is an operating system only serving the needs of Microsoft, a platform that burns bridges with the past and parts with internal betatesters by relying on mercy (or more often stupidity) of amateur testers of the Insider program. In brief, Windows 10 is a disaster that provides always new reasons for concern for PC users. Windows tendency for disaster recently took a turn that’s even more disturbing than usual, highlighting a potential risk for data and storage units of the aforementioned users.

Windows 10 has a lot of issues in managing system drives, a fact surfaced at the end of the last year with the inability to execute the chkdsk /f command without damaging the boot disk. Chkdsk, or “Check Disk” for friends, is one of the ancestral utilities of Windows (and MS-DOS before that) and is needed to fix errors on storage units. After upgrading to Windows 10 20H2, even such a fundamental task like disk checking can turn into a dangerous adventure with potentially devastating effects.

Microsoft fixed the Chkdsk bug in record time, but other recently surfaced bugs in disks management are still waiting for an official fix. The first error occurs when the user tries to access a particular attribute of the NTFS file system ($I30) through the cd c:\:$i30:$bitmap command, and leads to what seems a corruption of the unit’s file table pushing Windows to prompt a reboot for running Chkdsk. In general, the at-boot check-up should restore normal system operations, but in some cases the process damages the boot unit making Windows unusable.

Windows 10 bug

The $I30 attribute is a normal element of an NTFS unit, but in the case of Windows 10 (from version 1803 onward) it becomes a potential attack vector that can be exploited with no direct user interaction, by embedding the aforementioned command inside a link (.url) that can be downloaded from the Internet. It seems that this kind of bugs have been well known for years, Microsoft says it is (finally?) working on an official fix while third party companies have already released temporary countermeasures or updated Web browsers versions (Firefox).

Microsoft should also release a fix for another bug concerning a “unauthorized” access to disk properties through the Win32 API. By opening path \\.\globalroot\device\condrv\kernelconnect inside a Web browser or in other ways, Windows 10 (1709 and beyond) crashes instantly. In this case as well, an ill-intentioned fellow could exploit the bug to wreak havoc or to attack a system or an enterprise network (UPDATE: Patch Tuesday for February 2021 fixes the bug now tracked as CVE-2021-24098). Updates for Windows 10 are usually harbingers of even more problems and all-new disasters, but at least for sensitive storage matters Microsoft could avoid doing its usual shitty job and use employed testers that know what they are doing. Just for once, only to see how it feels…

Leggi questo post in italiano

Similar posts:

Leave a Reply

Your email address will not be published. Required fields are marked *