Page 1 of 1

New bug in Windows #MFT

Posted: Sat May 27, 2017 6:31 pm
by howiem
https://arstechnica.co.uk/information-t ... dows-7-8-1
and
https://www.theverge.com/2017/5/26/1569 ... h-bug-ntfs

Above site claims that a bug in Windows (but not Win10) will cause computers running Win 7 and 8.1(as well as the no longer supported Vista) to crash when accessing a web site with $MFT in a path name in an image.

My question is whether anyone at Invincea has tested this in a sandbox to see if using Samdboxie will prevent the bug from functioning

Re: New bug in Windows #MFT

Posted: Wed May 31, 2017 3:57 pm
by Barb@Invincea
Hello howiem,

Sandboxie will not stop this out of the box. However, you can tweak it by adding:
WriteFilePath=*$MFT* to your Sandboxie configuration file (Configure-->Edit Configuration )
Explorer may stay open in the Sandbox if you try to access the path, but it will not crash your computer. [At least it didn't during our tests (used Windows 8.1 x64 and Win 7 x86).]
If you decide to try it, please consider using a VM.

This tweak does not seem to block functionality so far, but we have not tested every combination. Keep that in mind when using it.
The devs are looking into this . We will also have to see if Microsoft decides to put a patch out there.

I'll post any updates here.

Regards,
Barb.-

Re: New bug in Windows #MFT

Posted: Wed May 31, 2017 4:48 pm
by howiem
Barb, Thank you.