A pre-installed application on Windows 10 has a major security hole
First introduced as part of Microsoft's Creators Update in 2016, Paint 3D was originally intended as a replacement for Microsoft Paint that has shipped with the company's operating system since Windows 10.
However, the 3D modeling software is not as expected. That's why Paint and Paint 3D continue to exist side by side on Windows. This could change soon as Paint 3D was not included in the recently leaked Windows 11 build.
Although difficult to exploit, the recently discovered vulnerability, now patched by Microsoft, could be another reason Paint 3D's era may be buried.
Vulnerability in Paint 3D (CVE-2021-31946) could be exploited by an attacker to execute arbitrary code after a user accesses or opens a malicious file following security advice from ZDI.
However, to exploit this vulnerability, an attacker would first need to gain privilege escalation on a targeted system before convincing a user to open a malicious file or website.
Earlier this year, ZDI discovered this vulnerability using a technique known as fuzzing. In February, they reported their findings to Microsoft. Thankfully, security researchers have not observed the exploit in practice or in pre-existing POC code, which means Windows users are safe for now.
At the same time, Microsoft has also released a patch to address the vulnerability through the Microsoft Store.
If you haven't set up automatic updates in the Microsoft Store, you can also download the update manually.
We'll have to wait and see if Paint 3D is dropped in the next version of Windows.
You should read it
- Uninstalling Paint will no longer be an 'impossible task'.
- Top 3 favorite hand-held paint sprayers today
- Microsoft continues to support Paint on Windows 10
- Paint on Windows 11 has new improvements, starting to roll out to the Dev channel
- Learn how to use Paint to edit photos on Windows
- Fix MS Paint not working on Windows
- Painter showed off painting with the top paint like Photoshop, who thought the people would show off 'good' equally
- Paint.NET 4.3.4 - Download Paint.NET 4.3.4 here
May be interested
- Detecting zero-day vulnerability in the Dropbox 10 Windows app, users pay attention!a group of free security researchers recently announced the zero-day vulnerability in the dropbox version of the windows app.
- Google revealed a critical flaw in Qualcomm's Adreno GPUthe google project zero team has publicly revealed a security hole that exists in the adreno gpu integrated on the snapdragon chip.
- Detected Critical Security Bugs Affecting All Versions of Windowsa critical security vulnerability, affecting all versions of windows, has just been discovered. notably, there are indications that hackers have exploited this security hole to attack users.
- Microsoft confirms a new serious security hole in Windows 10this is a hardware error and cannot issue a software patch. users can choose to better protect their computers or buy new devices with kernel dma security.
- Windows users need to update this software immediatelythis application's security hole could allow a hacker to execute malicious code on a user's windows computer remotely, potentially taking control.
- Microsoft fixes a serious security holeas announced last week, microsoft has released two updates for two security holes that are classified as serious
- Will the new trojan appear?last wednesday, a japanese-based security firm said it had discovered a trojan that exploited windows's image-processing security hole - just one day after microsoft gave it. issued b
- How to fix missing applications when updating to Windows 10 Fall Creators Updaterecently, users complained about a problem that caused certain applications to disappear from the operating system after installing the update. notably, this is not the first time a major update of windows 10 has damaged users' applications or installed operating systems.
- Discover a monster black hole 100,000 times bigger than the Sun, the second largest in the Milky Wayjapanese astronomers discovered a supermassive black hole hidden in a cloud of suspended gas near the center of the milky way with a diameter of up to 1400 billion km and a mass of 100,000 times the sun.
- Not yet released, but iOS 13 has a security hole that bypasses the lock screenios 13 will launch on september 19, but jose rodriguez, a security researcher, has discovered a flaw that allows hackers to bypass the lock screen on this version of ios.