search
HomeSystem TutorialWindows SeriesWindows 11's New Inetpub Folder is Hackable. Try This Temporary Fix - Make Tech Easier

Windows 11's New Inetpub Folder is Hackable. Try This Temporary Fix - Make Tech Easier

We previously discussed how the inetpub folder in Windows is crucial and should not be deleted due to security concerns. Ironically, the presence of this folder poses a security risk in itself. It's surprisingly simple for even non-administrative users to manipulate this folder, potentially compromising your PC's security. Let's delve into how the inetpub folder can be exploited and what you can do to protect your system until Microsoft offers a permanent fix.

How Can the Inetpub Folder Be Exploited?

Starting with the April 2025 cumulative update for Windows 11, an empty inetpub folder is now created in the C drive. This update aimed to fix a vulnerability that allowed attackers to use absent directories to insert symlinks into the Windows Update stack. However, attackers can still exploit this by replacing the folder with a directory junction, causing Windows Update to target the wrong location and fail.

Any user with access to your PC can execute a simple command without admin rights to alter the inetpub folder's final directory. As noted by security expert Kevin Beaumont, executing the command mklink /J C:\inetpub C:\Windows\System32\notepad.exe can redirect the folder to point to Notepad or any other file, leading to Windows update failures.

Internally, the Windows Servicing Stack operates as SYSTEM and regards C:\inetpub as a secure directory. It does not verify for reparse points or ownership, so when it attempts to place files there and encounters a junction to a file, the update process either fails or reverts.

A Temporary Fix for This Vulnerability

Microsoft has yet to address this vulnerability or confirm if a solution will be included in future updates. In the meantime, you can implement measures to reduce the risk of this vulnerability being exploited.

Creating a directory junction necessitates write/delete permissions on the parent folder. By removing these permissions from all user accounts, while still allowing SYSTEM and TrustedInstaller to retain them, you prevent any non-system process (including admins) from using mklink /J on “C:\inetpub”. Here’s how to do it:

On the C drive, right-click the inetpub folder and choose Properties.

Navigate to the Security tab and click on Advanced at the bottom.

Click Disable inheritance, and when prompted, select Remove all inherited permissions from this object.

Windows 11's New Inetpub Folder is Hackable. Try This Temporary Fix - Make Tech Easier

Click Add, then Select a principal. In the next window, type SYSTEM, click Check Names, and then OK.

Windows 11's New Inetpub Folder is Hackable. Try This Temporary Fix - Make Tech Easier

Under Basic permissions, choose Full control and click OK.

Windows 11's New Inetpub Folder is Hackable. Try This Temporary Fix - Make Tech Easier

Repeat the Add principal process, this time entering NT SERVICE\TrustedInstaller, granting Full control, and clicking OK. Close all windows by clicking OK.

Now, no users can access or modify the folder, and any attempt will trigger a Windows permission denied message. Windows and its updater will still have access to update the PC.

To undo these changes, revisit the Advanced Security Settings window, click Enable inheritance, and then Apply.

Windows 11's New Inetpub Folder is Hackable. Try This Temporary Fix - Make Tech Easier

This action will restore the original permissions. Simply delete the manually added SYSTEM and TrustedInstaller entries by selecting them and clicking Remove.

Windows 11's New Inetpub Folder is Hackable. Try This Temporary Fix - Make Tech Easier

This approach should safeguard your PC until Microsoft resolves the vulnerability. The adjusted permissions should facilitate smooth Windows updates. If you encounter issues with Windows updates, consider resetting the Windows update components before reverting these permissions.

The above is the detailed content of Windows 11's New Inetpub Folder is Hackable. Try This Temporary Fix - Make Tech Easier. For more information, please follow other related articles on the PHP Chinese website!

Statement
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
Excel Data Source Reference Not ValidExcel Data Source Reference Not ValidMay 14, 2025 pm 04:38 PM

Are you facing the annoying "Excel data source reference not valid" error? Don't fret, we're here to assist you in resolving this issue and getting your spreadsheets functioning smoothly again. Microsoft Excel, with its vast array of tools

Excel Found Unreadable Content - How to Fix the IssueExcel Found Unreadable Content - How to Fix the IssueMay 14, 2025 pm 04:37 PM

Learn about the most effective solutions to tackle the "Excel found unreadable content" error in XLSX files. We recognize the challenges you might encounter when facing this error, which can make it difficult to access your essential data.D

Fix the 'No Internet, Secured' Problem in Windows 10Fix the 'No Internet, Secured' Problem in Windows 10May 14, 2025 pm 04:35 PM

Many users who upgrade to Windows 10 encounter WiFi connectivity issues, experiencing slow internet or complete inability to connect. If you're facing the latter, you'll notice the "No Internet, secured" message next to your WiFi network in

Solved: No Internet Connection Windows 10Solved: No Internet Connection Windows 10May 14, 2025 pm 04:33 PM

Windows 10 updates can occasionally introduce new issues to your system, including the No Internet Connection error, which can prevent your computer from accessing the internet. Fortunately, this frustrating problem can be resolved using our outlined

How to Improve Game Data Loading Times in Windows - Make Tech EasierHow to Improve Game Data Loading Times in Windows - Make Tech EasierMay 14, 2025 pm 04:32 PM

To enhance gaming performance, many games load assets on-the-fly, making an SSD highly beneficial for reducing load times. If your SSD is slow or you're still using an HDD, you might experience extended loading times, stuttering, and fluctuating FPS.

Microsoft Word Keeps Freezing in Windows 10 - 10 ways to fix ItMicrosoft Word Keeps Freezing in Windows 10 - 10 ways to fix ItMay 14, 2025 pm 04:31 PM

Are you facing issues with Microsoft Word freezing on your Windows 10 system? This can be highly frustrating, especially when you're in the middle of important work.When Microsoft Word keeps freezing on Windows 10 during your tasks, it indicates an u

What to Do When Windows Update Keeps Failing on Windows 10What to Do When Windows Update Keeps Failing on Windows 10May 14, 2025 pm 04:30 PM

Windows 10, a widely used operating system around the world, often faces various issues despite its widespread adoption. One common problem is the recurring failure of the Windows Update feature, which prevents users from updating their systems.If yo

Spotify Web Player Not Working? What To Do?Spotify Web Player Not Working? What To Do?May 14, 2025 pm 04:28 PM

If you're struggling with the Spotify web player not functioning properly, you're not alone. Many users face similar issues when trying to enjoy their favorite music on this popular streaming platform. Fortunately, there are several troubleshooting s

See all articles

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

SublimeText3 English version

SublimeText3 English version

Recommended: Win version, supports code prompts!

PhpStorm Mac version

PhpStorm Mac version

The latest (2018.2.1) professional PHP integrated development tool

SAP NetWeaver Server Adapter for Eclipse

SAP NetWeaver Server Adapter for Eclipse

Integrate Eclipse with SAP NetWeaver application server.

Safe Exam Browser

Safe Exam Browser

Safe Exam Browser is a secure browser environment for taking online exams securely. This software turns any computer into a secure workstation. It controls access to any utility and prevents students from using unauthorized resources.

WebStorm Mac version

WebStorm Mac version

Useful JavaScript development tools