logo

'MagicDot' Windows Weakness Allows Unprivileged Rootkit Activity

ID: fe1a91b5-fe8c-5385-b558-3d14900d6ad0

STIX ID: report--fe1a91b5-fe8c-5385-b558-3d14900d6ad0

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-04-19

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

Or Yair (SafeBreach) disclosed 'MagicDot', a set of issues in Windows DOS-to-NT path conversion where automatic removal of trailing periods and spaces allows attackers to conceal files, impersonate legitimate paths, and obtain rootkit-like stealth without kernel access or admin rights; four related vulnerabilities were identified (notably an RCE via archive extraction and EoP via shadow-copy restore), several were patched by Microsoft, but the underlying conversion behavior remains and could enable further impactful exploitation — detection should focus on rogue trailing dots/spaces in file paths and developers should prefer NT paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.