Thecyberexpress Microsoft Recall Flaw Allows Data Extraction via DLL Injection
Article Content
- •TotalRecall Reloaded exploits a flaw in AIXHost.exe, allowing data extraction post-authentication.
- •Microsoft claims the behavior is within the documented security design and not a vulnerability.
- •The attack requires no special privileges beyond those of the logged-in user.
Researchers have identified a vulnerability in Microsoft's redesigned Recall feature for Windows 11, which allows attackers to extract decrypted user data, including screenshots and metadata. The flaw is attributed to the AIXHost.exe process, which lacks sufficient protections, enabling DLL injection attacks without requiring administrative privileges. The TotalRecall Reloaded tool exploits this vulnerability by embedding itself into AIXHost.exe after user authentication through Windows Hello. Microsoft has defended the architecture, stating that the behavior operates within the documented security design and does not constitute a vulnerability. The incident follows a previous discovery by researcher Alexander Hagenah in 2024, which led to Recall's temporary suspension. Microsoft redesigned Recall with enhanced security features, but the current issue highlights a gap in the implementation. No specific CVEs have been assigned to this vulnerability yet. The attack can occur with standard user permissions, raising concerns about user data security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…