


Windows 11's New Inetpub Folder is Hackable. Try This Temporary Fix - Make Tech Easier
We previously discussed how the inetpub folder in Windows is crucial and should not be deleted due to security concerns. Ironically, the presence of this folder poses a security risk in itself. It's surprisingly simple for even non-administrative users to manipulate this folder, potentially compromising your PC's security. Let's delve into how the inetpub folder can be exploited and what you can do to protect your system until Microsoft offers a permanent fix.
How Can the Inetpub Folder Be Exploited?
Starting with the April 2025 cumulative update for Windows 11, an empty inetpub folder is now created in the C drive. This update aimed to fix a vulnerability that allowed attackers to use absent directories to insert symlinks into the Windows Update stack. However, attackers can still exploit this by replacing the folder with a directory junction, causing Windows Update to target the wrong location and fail.
Any user with access to your PC can execute a simple command without admin rights to alter the inetpub folder's final directory. As noted by security expert Kevin Beaumont, executing the command mklink /J C:\inetpub C:\Windows\System32\notepad.exe can redirect the folder to point to Notepad or any other file, leading to Windows update failures.
Internally, the Windows Servicing Stack operates as SYSTEM and regards C:\inetpub as a secure directory. It does not verify for reparse points or ownership, so when it attempts to place files there and encounters a junction to a file, the update process either fails or reverts.
A Temporary Fix for This Vulnerability
Microsoft has yet to address this vulnerability or confirm if a solution will be included in future updates. In the meantime, you can implement measures to reduce the risk of this vulnerability being exploited.
Creating a directory junction necessitates write/delete permissions on the parent folder. By removing these permissions from all user accounts, while still allowing SYSTEM and TrustedInstaller to retain them, you prevent any non-system process (including admins) from using mklink /J on “C:\inetpub”. Here’s how to do it:
On the C drive, right-click the inetpub folder and choose Properties.
Navigate to the Security tab and click on Advanced at the bottom.
Click Disable inheritance, and when prompted, select Remove all inherited permissions from this object.
Click Add, then Select a principal. In the next window, type SYSTEM, click Check Names, and then OK.
Under Basic permissions, choose Full control and click OK.
Repeat the Add principal process, this time entering NT SERVICE\TrustedInstaller, granting Full control, and clicking OK. Close all windows by clicking OK.
Now, no users can access or modify the folder, and any attempt will trigger a Windows permission denied message. Windows and its updater will still have access to update the PC.
To undo these changes, revisit the Advanced Security Settings window, click Enable inheritance, and then Apply.
This action will restore the original permissions. Simply delete the manually added SYSTEM and TrustedInstaller entries by selecting them and clicking Remove.
This approach should safeguard your PC until Microsoft resolves the vulnerability. The adjusted permissions should facilitate smooth Windows updates. If you encounter issues with Windows updates, consider resetting the Windows update components before reverting these permissions.
The above is the detailed content of Windows 11's New Inetpub Folder is Hackable. Try This Temporary Fix - Make Tech Easier. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics











KB5054979 is a cumulative security update released on March 27, 2025, for Windows 11 version 24H2. It targets .NET Framework versions 3.5 and 4.8.1, enhancing security and overall stability. Notably, the update addresses an issue with file and directory operations on UNC shares using System.IO APIs. Two installation methods are provided: one through Windows Settings by checking for updates under Windows Update, and the other via a manual download from the Microsoft Update Catalog.

Nanoleaf's Pegboard Desk Dock: A Stylish and Functional Desk Organizer Tired of the same old charging setup? Nanoleaf's new Pegboard Desk Dock offers a stylish and functional alternative. This multifunctional desk accessory boasts 32 full-color RGB

Turn your Windows 11 PC into a Bluetooth speaker and enjoy your favorite music from your phone! This guide shows you how to easily connect your iPhone or Android device to your computer for audio playback. Step 1: Pair Your Bluetooth Device First, pa

ASUS ROG Zephyrus G14 Esports Laptop Special Offer! Buy ASUS ROG Zephyrus G14 Esports Laptop now and enjoy a $300 offer! Original price is $1999, current price is only $1699! Enjoy immersive gaming experience anytime, anywhere, or use it as a reliable portable workstation. Best Buy currently offers offers on this 2024 14-inch ASUS ROG Zephyrus G14 e-sports laptop. Its powerful configuration and performance are impressive. This ASUS ROG Zephyrus G14 e-sports laptop costs 16 on Best Buy

Unlock Hidden Windows Features for a Smoother Experience! Discover surprisingly useful Windows functionalities that can significantly enhance your computing experience. Even seasoned Windows users might find some new tricks here. Dynamic Lock: Auto

Improve mouse accuracy: Disable Windows 11 mouse acceleration function The mouse cursor moves too fast on the screen, even if you only move the mouse a few centimeters? This is what the mouse acceleration function is. This article will guide you on how to disable this feature to better control mouse movement. Is it wise to disable mouse acceleration? There is no direct "Mouse Acceleration" option in Windows systems. Instead, it is the "Enhanced Pointer Precision" setting, which Microsoft sees as a mouse acceleration feature. When this feature is enabled, the mouse's DPI (dots per inch) setting takes effect. It controls the relationship between the physical movement speed of the mouse and the distance the cursor moves on the screen. Move the mouse slowly, Windows will reduce the effective DPI and the cursor moves shorter

In today's touchscreen world, the satisfying tactile feedback of physical controls is a welcome change. That's why a keyboard with a large volume knob is surprisingly appealing. I recently experienced this firsthand, and it's been a revelation. For

The mouse is a vital component to getting work done on your PC. But when you’re stuck with a faulty mouse, you can run into a few problems including the inability to right-click. But the good news is that there are definitely ways t
