Microsoft’s Patch: From Fix to Fiasco – The Inetpub Incident!
Microsoft’s latest patch brought back the inetpub folder, intended to mitigate a vulnerability, but ended up as the star of a security blooper. With just a simple mklink command, anyone can hijack updates without admin rights. Time to dust off those sysadmin capes and scan for those sneaky junctions!

Hot Take:
Looks like Microsoft’s attempt to patch their patch has left them in a bit of a folder frenzy. Who knew an empty directory could cause such a stir? But hey, at least they’re keeping security researchers on their toes and giving sysadmins a new scavenger hunt to play!
Key Points:
- The infamous c:inetpub folder is back, courtesy of a Microsoft patch.
- Security researcher Kevin Beaumont discovered a new vulnerability introduced by the patch.
- Using mklink with the /j parameter can redirect Windows Update, causing errors.
- No admin rights are required for this exploit, making it accessible to all users.
- Microsoft has been informed, but they’re currently silent on the issue.
Already a member? Log in here