News: 0179880322

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft Disables Preview In File Explorer To Block Attacks (bleepingcomputer.com)

(Monday October 27, 2025 @12:34AM (EditorDavid) from the explorer-horrors dept.)


Slashdot reader [1]joshuark writes:

> Microsoft says that the File Explorer (formerly Windows Explorer) now automatically blocks previews for files downloaded from the Internet to block credential theft attacks via malicious documents, [2]according to a report from BleepingComputer . This attack vector is particularly concerning because it requires no user interaction beyond selecting a file to preview and removes the need to trick a target into actually opening or executing it on their system.

>

> For most users, no action is required since the protection is enabled automatically with the October 2025 security update, and existing workflows remain unaffected unless you regularly preview downloaded files.

>

> "This change is designed to enhance security by preventing a vulnerability that could leak NTLM hashes when users preview potentially unsafe files," [3]Microsoft says in a support document published Wednesday .

>

> It is important to note that this may not take effect immediately and could require signing out and signing back in.



[1] https://slashdot.org/~joshuark

[2] https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-preview-pane-for-downloads-to-block-ntlm-theft-attacks/

[3] https://support.microsoft.com/en-us/topic/file-explorer-automatically-disables-the-preview-feature-for-files-downloaded-from-the-internet-56d55920-6187-4aae-a4f6-102454ef61fb



Or, and stay with me here (Score:2)

by Krishnoid ( 984597 )

Disable network/Internet access for the preview function, maybe via sandbox? Crazy, I know.

Ah, preview! (Score:2)

by johnnys ( 592333 )

"Preview". Also known as "Let me help you by running this anonymous code without asking or even checking to see it is is suspicious and I won't even give you the chance to decide whether or not to run it!"

"Microsoft considered harmful."

Brandy Davis, an outfielder and teammate of mine with the Pittsburgh Pirates,
is my choice for team captain. Cincinnati was beating us 3-1, and I led
off the bottom of the eighth with a walk. The next hitter banged a hard
single to right field. Feeling the wind at my back, I rounded second and
kept going, sliding safely into third base.
With runners at first and third, and home-run hitter Ralph Kiner at
bat, our manager put in the fast Brandy Davis to run for the player at first.
Even with Kiner hitting and a change to win the game with a home run, Brandy
took off for second and made it. Now we had runners at second and third.
I'm standing at third, knowing I'm not going anywhere, and see Brandy
start to take a lead. All of a sudden, here he comes. He makes a great slide
into third, and I scream, "Brandy, where are you going?" He looks up, and
shouts, "Back to second if I can make it."
-- Joe Garagiola, "It's Anybody's Ball Game"