'MagicDot' Windows Weakness Allows Unprivileged Rootkit Activity
ID: fe1a91b5-fe8c-5385-b558-3d14900d6ad0
STIX ID: report--fe1a91b5-fe8c-5385-b558-3d14900d6ad0
Feed Name: Dark Reading
Date Published: 2024-04-19
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Or Yair (SafeBreach) disclosed 'MagicDot', a set of issues in Windows DOS-to-NT path conversion where automatic removal of trailing periods and spaces allows attackers to conceal files, impersonate legitimate paths, and obtain rootkit-like stealth without kernel access or admin rights; four related vulnerabilities were identified (notably an RCE via archive extraction and EoP via shadow-copy restore), several were patched by Microsoft, but the underlying conversion behavior remains and could enable further impactful exploitation — detection should focus on rogue trailing dots/spaces in file paths and developers should prefer NT paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
