Is autorun malware a security issue for organizations running legitimate software, or is it just something that...
affects users running pirated software? Are organizations that run legacy software susceptible to autorun malware?
Ask the Expert!
SearchSecurity expert Nick Lewis is standing by to answer your questions about enterprise security threats. Submit your question via email. (All questions are anonymous.)
The "autorun" function was abused by malware authors shortly after its debut many years ago. It was intended to make non-hard disk drives -- particularly optical drives -- more user-friendly. When most users put a CD into their computer, they want it to automatically start playing. This same functionality allowed users to quickly install legitimate software from CD-ROMs, and later, DVDs.
However, smart malware authors began exploiting autorun. The function allowed attackers to quickly infect a system by executing a malicious file stored on portable media enabled for autorun -- such as optical discs, network drives and flash drives -- when the file is automatically executed. Today, for security reasons, most client computers have autorun disabled and require users to manually execute files on portable media, whether it's running an installer or playing a music CD. This is not limited to pirated versions of Windows, but pirated versions may be more susceptible to malware since they get security updates, but they might not get upgrades or updates with new functionality.
Old versions of Windows might not allow you to disable autorun, but current versions do (another reason to upgrade or discard legacy Windows systems). Disabling autorun on older systems could potentially affect legacy software that requires a CD in the CD-ROM drive, and require users to manually start some software installations. It's a small inconvenience for users for the sake of improved security, since autorun was abused so widely by malware.
Dig Deeper on Malware, Viruses, Trojans and Spyware
Related Q&A from Nick Lewis
Vonteera adware has the ability to disable antimalware software on endpoint devices. Expert Nick Lewis explains how enterprises can prevent this ...continue reading
ModPOS, a new POS malware, compromised millions of credit card accounts in 2015. Expert Nick Lewis explains how cybercriminals use this malware and ...continue reading
Amex cards have been discovered to be vulnerable to credit card hacking. Expert Nick Lewis explains how this happens, and what can be done about Chip...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.