How was Windows Store app able to download adware to a Windows 10 PC?

    How was Windows Store app able to download adware to a Windows 10 PC?

    How was Windows Store app able to download adware to a Windows 10 PC?


    Posted: 08 May 2016

    Apps from the Windows Store run in a highly restricted sandbox and have to be approved before they can be listed. So why was this app able to automatically download an executable file that multiple virus scanners identified as potentially dangerous?

    One of the biggest selling points of the Windows Store is its promise of safety. Apps have to be approved to make it into the store, and the sandbox in which apps run should prevent them from causing any damage or installing malware or unwanted software.

    That doesn't mean developers can't try shady tricks. But their options are extremely limited, which is why I was surprised to find an app in the Windows Store last week that actually succeeded in downloading adware to a Windows 10 PC.

    An unsophisticated user might have been fooled into going one step further and running that software, resulting in the installation of an annoying piece of adware and potentially much worse...


    Source: How was this Windows Store app able to download adware to a Windows 10 PC? | ZDNet
    Brink's Avatar Posted By: Brink
    08 May 2016


  1. Posts : 5,452
    Windows 11 Home
       #1

    The author got a little overexcited. For starters it is PUP, secondly, it merely opened a link, the browser downloaded it, so no sandbox was breached. I guess, that the proclaimed update downloaded some script, which caused a link to open.
      My Computer


  2. Posts : 16,325
    W10Prox64
       #2

    TairikuOkami said:
    The author got a little overexcited. For starters it is PUP, secondly, it merely opened a link, the browser downloaded it, so no sandbox was breached. I guess, that the proclaimed update downloaded some script, which caused a link to open.
    Yes, but the MS apps are supposed to be "safe". This one reached outside the sandbox in an attempt to harm the system.
      My Computer


  3. Posts : 5,452
    Windows 11 Home
       #3

    The problem is, that it is a download app. The app itself and its content are sandboxed, but not, what it downloads.
    Just like a browser, eg Chrome, it is sandboxed, but a user can download any malware and run it, sandbox does not apply.
      My Computer


  4. Posts : 16,325
    W10Prox64
       #4

    TairikuOkami said:
    The problem is, that it is a download app. The app itself and its content are sandboxed, but not, what it downloads.
    Just like a browser, eg Chrome, it is sandboxed, but a user can download any malware and run it, sandbox does not apply.
    Correct, but it gives a false sense of security to unsuspecting, every-day-novice users.
      My Computer


  5. Posts : 5,452
    Windows 11 Home
       #5

    simrick said:
    Correct, but it gives a false sense of security to unsuspecting, every-day-novice users.
    Well so do security companies and people then act surprised, how could they get infected with AV installed.
    Accidents happen, but they help to improve safety, I guess, that MS will respond by some nice improvements.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 15:21.
Find Us




Windows 10 Forums