Linux on Windows 10 Poses a Security Risk
Security researchers have already notified Microsoft; some fixes are available
As the instances of Linux virtual machines are increasing on Microsoft Azure, Microsoft is looking at Linux as a development platform. To enable sysadmins and developers to manage their Linux machines from Windows, without having to resort to a VM, the company worked with Canonical to bring Ubuntu's version of the Bash shell to Windows 10. To achieve this, Microsoft has built a new subsystem within Windows called the Windows Subsystem for Linux (WSL). Ubuntu for Windows runs on top of the WSL infrastructure to offer Linux developer tools on Windows, but according to Crowdstrike chief architect Alex Ionescu, this design is creating some serious security issues.
Ionescu, who delivered a talk on WSL issues at the recent BlackHat security conference, has already reported his findings to Microsoft, and some of the issues have already been fixed. In an interview with eWeek, Ionescu said, "There are a number of ways that Windows applications could inject code, modify memory, and add new threats to a Linux application running on Windows."
Ionescu also added that the Linux environment running in Windows is less secure because of compatibility issues with the host operating system. He noted that Microsoft's whitelisting service for Windows application, AppLocker, doesn't work with Linux applications.
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Linux Mint 22.3 Now Available with New Tools
Linux Mint 22.3 has been released with a pair of new tools for system admins and some pretty cool new features.
-
New Linux Malware Targets Cloud-Based Linux Installations
VoidLink, a new Linux malware, should be of real concern because of its stealth and customization.
-
Say Goodbye to Middle-Mouse Paste
Both Gnome and Firefox have proposed getting rid of a long-time favorite Linux feature.
-
Manjaro 26.0 Primary Desktop Environments Default to Wayland
If you want to stick with X.Org, you'll be limited to the desktop environments you can choose.
-
Mozilla Plans to AI-ify Firefox
With a new CEO in control, Mozilla is doubling down on a strategy of trust, all the while leaning into AI.
-
Gnome Says No to AI-Generated Extensions
If you're a developer wanting to create a new Gnome extension, you'd best set aside that AI code generator, because the extension team will have none of that.
-
Parrot OS Switches to KDE Plasma Desktop
Yet another distro is making the move to the KDE Plasma desktop.
-
TUXEDO Announces Gemini 17
TUXEDO Computers has released the fourth generation of its Gemini laptop with plenty of updates.
-
Two New Distros Adopt Enlightenment
MX Moksha and AV Linux 25 join ranks with Bodhi Linux and embrace the Enlightenment desktop.
-
Solus Linux 4.8 Removes Python 2
Solus Linux 4.8 has been released with the latest Linux kernel, updated desktops, and a key removal.
