Windows 11 updates silently create a mysterious folder on the C drive
The April security updates for Windows 11 silently created a new empty folder on the C drive.
Windows isn't the most secure operating system out there, and new vulnerabilities are constantly being discovered. However, this latest vulnerability can infect your PC in as little as 300 milliseconds, which means you should update your PC immediately.
Hackers can break into your PC in the blink of an eye
This vulnerability allows attackers to exploit the Mobile devices feature of Windows 11 through advanced DLL hijacking techniques. The vulnerability is identified as CVE-2025-24076 and has been cataloged in Microsoft's security vulnerability database.
Specifically, the bug targets a DLL file loaded by the Windows 11 camera feature, replacing it with a malicious DLL that gives an attacker elevated privileges on your system. Windows uses this feature to let you use your phone as a webcam, but it's also an attacker's entry point into your system.
In an example presented by John Ostrowski on his Compass Security blog, the attack was successful on an updated Windows 11 installation and created a file in the C: drive that only users with admin rights could access. This method can be used to inject malware onto a target PC and execute it with admin rights.
An attacker has only about 300 milliseconds to replace the DLL used by the mobile device with a malicious version. However, Ostrowski, along with James Forshaw, found a way to stop the program when the DLL was accessed. Then, using Microsoft's Detours library, they intercepted the mobile device's calls to the target DLL and replaced it with a malicious version that allowed for privilege escalation.
Another vulnerability tracked as CVE-2025-24994 was also discovered during this process, which could potentially allow user-to-user attacks. However, CVE-2025-24076 is a more pressing issue.
Update your system now to protect yourself!
The vulnerabilities were discovered on September 20, 2024, and reported to Microsoft on October 8. Microsoft took several months to patch the bugs, but released an update on March 11, 2025 to fix the issue. The vulnerabilities have not yet been exploited in the wild, and the company believes that exploitation is unlikely.
Exploitation of the bug also requires user interaction, albeit with low privileges. An attacker must first log in to the target system to trigger an event that can exploit the vulnerability, making the attack less successful.
As a Windows user, as long as you have installed Microsoft's March security updates, you should be protected from the issue. If you haven't, you should update to the latest version of Windows available. Be careful, though, scammers are using fake Windows updates to steal your files, so make sure you only use the Windows Update section of your operating system settings to install any updates.
The April security updates for Windows 11 silently created a new empty folder on the C drive.
The Spotlight wallpaper on the Windows 11 desktop and lock screen has an annoying “Learn More About This Picture” icon. Here is a guide to remove the “Learn More About This Picture” Windows 11 icon.
The Apps & Features control panel is the settings equivalent to the Programs and Features tool from the Control Panel.
The Libraries folder in Windows 11 is hidden in the File Explorer interface, but you can easily show it again with just a few taps.
Are you getting a High Memory Usage Detected warning while browsing on Microsoft Edge? It means that some browser processes are using too much memory (RAM).
Follow these steps to set up speech recognition on your Windows laptop or PC.
In many cases, it is usually due to virus attacks that the hidden folders of the system cannot be displayed even after activating the “Show hidden files and folders” option in Folder Options. Some of the following methods will help to handle this problem.
Sometimes you still need to turn off the firewall to perform certain functions. The 3 ways to turn off the Win 10 firewall below will help you in such situations.
If you're looking for a quicker method, here's how to add a dedicated shutdown shortcut to your Windows 11 desktop or taskbar.
Windows 11 doesn't support the JPEG X image format by default, but you can install an add-on that does. Here's how to add JPEG XL support in Windows 11.
In the process of pinning applications, sometimes we encounter some errors such as not being able to pin the application to the Taskbar. Below are some ways to fix the error of not being able to pin the application to the Windows 11 Taskbar.
Windows BitLocker offers an easy-to-use solution for encrypting your hard drive. However, it also has its drawbacks, so it may not be a great choice for everyone.
This guide will show you how to overwrite (securely erase) deleted data on a drive so that it cannot be recovered or accessed in Windows 10 and Windows 11.
If you regularly use Copilot on Windows 11, there is a very simple way to quickly access Copilot, which is to add Copilot to the right-click menu.
Adding a printer to Windows 10 is simple, although the process for wired devices will be different than for wireless devices.