There’s a bug in the UWP API that lets appropriately programmed apps look at all of your data. Günter Born says: (The malicious UWP) app is not limite
[See the full post at: Newly discovered data access breach in Win10 UWP (Metro, “Store”) apps]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Newly discovered data access breach in Win10 UWP (Metro, “Store”) apps
Home » Forums » Newsletter and Homepage topics » Newly discovered data access breach in Win10 UWP (Metro, “Store”) apps
- This topic has 17 replies, 11 voices, and was last updated 6 years, 4 months ago.
Tags: broadFileSystemAccess
AuthorTopicViewing 5 reply threadsAuthorReplies-
WildBill
AskWoody PlusOctober 27, 2018 at 3:03 pm #227597Well, that tears it. Even if Microsoft fixes the bug, I’ll never move to Win10 whatever. Neither Home nor Pro! Yes, I know it will be fixed… but what’s to stop some coder from breaking it again? It’s always been a matter of trust, but MS just lost mine for good when it comes to Windows 10. As long as they don’t break Win8.1 before 2023… bugs start popping up after January 2020, then Linux Mint, here I come!
Bought a refurbished Windows 10 64-bit, currently updated to 22H2. Have broke the AC adapter cord going to the 8.1 machine, but before that, coaxed it into charging. Need to buy new adapter if wish to continue using it.
Wild Bill Rides Again...4 users thanked author for this post.
-
Susan Bradley
ManagerOctober 27, 2018 at 9:45 pm #227629The store process means that apps are vetted so isn’t this a theoretical attack rather than one we will see in reality? It’s like the iPhone bugs that they say “first you have to jailbreak the device”…. well yeah….
Susan Bradley Patch Lady/Prudent patcher
1 user thanked author for this post.
-
anonymous
Guest -
Susan Bradley
ManagerOctober 28, 2018 at 1:55 am #227642
-
-
-
Jan K.
AskWoody Lounger -
lurks about
AskWoody LoungerOctober 28, 2018 at 9:25 am #227670What I understood was the problem is UWP apps were granted extensive file reading (writing?) privileges even when the developer did not invoke them or request them. Thus it sounds like a carefully crafted app could harvest files from anywhere on the box and send them to their mothership. How practical this mode would be; I do not know.
1 user thanked author for this post.
-
anonymous
GuestSeff
AskWoody PlusOctober 27, 2018 at 3:21 pm #227601Surely not! Windows 10 is the most secure version of Windows, is it not?
Thanks for the info, Woody.
2 users thanked author for this post.
-
Charlie
AskWoody Plus
lanceboil
AskWoody Loungerb
AskWoody_MVPOctober 27, 2018 at 6:18 pm #227618There’s a bug in the UWP API that lets appropriately programmed apps look at all of your data.
But there are unlikely to be any such apps (apart from Microsoft’s App Installer and Diagnostics Data Viewer) because;
If you submit an app to the Store that declares this capability, you will need to supply additional descriptions of why your app needs this capability, and how it intends to use it.
Docs / Windows / UWP / Develop / Files, folders, and libraries / File access permissionsAnd the capability can be disabled per device, per user or per app.
As for the app crash on 1809; that sounds like a programmer error:
Some capabilities provide apps with access to a sensitive resource. These resources are considered sensitive because they can access the user’s personal data or cost the user money. Privacy settings, managed by the Settings app, let the user dynamically control access to sensitive resources. Thus, it’s important that your app doesn’t assume a sensitive resource is always available.
Docs / Windows / UWP / Develop / Packaging apps / App capability declarations1 user thanked author for this post.
-
woody
Manager
mn–
AskWoody LoungerOctober 29, 2018 at 3:14 am #227837… so, let’s see…
1. UWP apps from outside the Store have direct filesystem access on by default in previous versions of Windows 10, but off by default in 1809. The bug is that the permission dialog doesn’t display automatically on first instance of the specific app requiring this permission.
2. UWP apps that need direct filesystem access and don’t have it, throw an exception that defaults to crashing the app unless caught. The permission state can change while app is running and takes effect immediately.
Now, unless there’s something even weirder going on, surely the user’s UWP apps still run in the normal user context and thus only have at most as much capability as the user’s non-UWP processes, thus not causing any inherent extra risk just due to being UWP? Such as in this case with a business-specific internal app, apparently…?
What I find potentially somewhat risky is the unexpected state change, which logically might prevent the app from saving its data to disk, thus having the potential for data loss. This is not markedly different from non-UWP apps running into an unexpected permissions problem at file open time but might differ for files that were already open, or does the UWP platform prevent continuously open files or something?
Not going into whatever may be going on with the Store – the “vetting” processes would reduce risks but not eliminate.
-
mn–
AskWoody LoungerOctober 29, 2018 at 8:23 am #227856… hm, it seems that the “broad filesystem access” privacy settings entry just isn’t there at all in at least W10 1709…
Now, from https://stackoverflow.com/questions/49728846/uwp-c-sharp-folderpicker-without-dialog and elsewhere, broad filesystem access was supposed to either not exist or default to off in older versions.
Anyone know which versions are vulnerable, then? From context I’d guess at least 1803 but could go way back…
-
b
AskWoody_MVPNovember 8, 2018 at 12:46 pm #231464Looks to me like only 1803 (not earlier versions) could possibly have been regarded as vulnerable, and 1809 is not.
But the guy who discovered the bug has now updated his blog entry, and I’m not convinced that he ever considered it to be exploitable:
Update: There has been a bit of misunderstanding on how this works. The broadFileSystemAccess is a restricted capability that an application could be granted, it is not an API. As a developer as well, I have to opt-in to using the capability. Any application in the store with the capability goes through extra verification by the Store team before any user gets it and the user is aware they are granting the application the permission to use the capability as well.
Important information about the new capability of broadFileSystemAccess in UWP apps
-
b
AskWoody_MVPJanuary 17, 2019 at 10:09 am #312781Fixed:
Addresses a privacy issue with apps that obtain the BroadFileSystemAccess capability without a user’s consent.
Viewing 5 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Small desktops
by
Susan Bradley
42 minutes ago -
Totally disable Bitlocker
by
CWBillow
4 hours, 1 minute ago -
Totally disable Bitlocker
by
CWBillow
5 hours, 40 minutes ago -
Windows 11 ad from Campaign Manager in Windows 10 (Awaiting moderation)
by
Jim McKenna
9 hours, 9 minutes ago -
Phishers extract Millions from HMRC accounts..
by
Microfix
17 hours, 48 minutes ago -
Windows 10 22H2 Update today (5 June) says up-to-date but last was 2025-04
by
Alan_uk
19 hours, 40 minutes ago -
Thoughts on Malwarebytes Scam Guard for Mobile?
by
opti1
22 hours, 49 minutes ago -
Mystical Desktop
by
CWBillow
23 hours, 2 minutes ago -
Meta and Yandex secretly tracked billions of Android users
by
Alex5723
4 hours, 20 minutes ago -
MS-DEFCON 2: Do you need that update?
by
Susan Bradley
13 hours, 13 minutes ago -
CD/DVD drive is no longer recognized
by
WSCape Sand
1 day, 14 hours ago -
Windows 11 24H2 Default Apps stuck on Edge and Adobe Photoshop
by
MikeBravo
1 day, 17 hours ago -
North Face and Cartier customer data stolen in cyber attacks
by
Alex5723
1 day, 15 hours ago -
What is wrong with simple approach?
by
WSSpoke36
1 day, 7 hours ago -
Microsoft-Backed Builder.ai Set for Bankruptcy After Cash Seized
by
Alex5723
2 days, 2 hours ago -
Location, location, location
by
Susan Bradley
17 hours, 1 minute ago -
Cannot get a task to run a restore point
by
CWBillow
2 days, 4 hours ago -
Frustrating search behavior with Outlook
by
MrJimPhelps
1 day, 18 hours ago -
June 2025 Office non-Security Updates
by
PKCano
2 days, 14 hours ago -
Secure Boot Update Fails after KB5058405 Installed
by
SteveIT
17 hours, 21 minutes ago -
Firefox Red Panda Fun Stuff
by
Lars220
2 days, 14 hours ago -
How start headers and page numbers on page 3?
by
Davidhs
3 days, 1 hour ago -
Attack on LexisNexis Risk Solutions exposes data on 300k +
by
Nibbled To Death By Ducks
2 days, 3 hours ago -
Windows 11 Insider Preview build 26200.5622 released to DEV
by
joep517
3 days, 9 hours ago -
Windows 11 Insider Preview build 26120.4230 (24H2) released to BETA
by
joep517
3 days, 9 hours ago -
MS Excel 2019 Now Prompts to Back Up With OneDrive
by
lmacri
2 days, 23 hours ago -
Firefox 139
by
Charlie
2 days, 16 hours ago -
Who knows what?
by
Will Fastie
1 day, 18 hours ago -
My top ten underappreciated features in Office
by
Peter Deegan
3 days, 10 hours ago -
WAU Manager — It’s your computer, you are in charge!
by
Deanna McElveen
1 day, 4 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.