{"id":17525,"date":"2025-04-13T21:28:12","date_gmt":"2025-04-13T21:28:12","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/17525\/"},"modified":"2025-04-13T21:28:12","modified_gmt":"2025-04-13T21:28:12","slug":"microsofts-new-windows-update-1-billion-users-warned-do-not-delete","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/17525\/","title":{"rendered":"Microsoft\u2019s New Windows Update \u2014 1 Billion Users Warned: Do Not Delete"},"content":{"rendered":"<p class=\"color-body light-text\" role=\"button\">Do not delete this Windows update folder, Microsoft warns.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>Windows users have a lot on their collective plate when it comes to matters of security, that\u2019s for sure. There\u2019s the zero-day vulnerability that wants to <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/03\/27\/windows-passwords-at-risk-as-new-0-day-confirmed-act-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/03\/27\/windows-passwords-at-risk-as-new-0-day-confirmed-act-now\/\" target=\"_self\" aria-label=\"steal your Windows passwords\" rel=\"noopener\">steal your Windows passwords<\/a>, hackers <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/03\/31\/hackers-bypass-windows-defender-security-what-you-need-to-know\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/03\/31\/hackers-bypass-windows-defender-security-what-you-need-to-know\/\" target=\"_self\" aria-label=\"bypassing Windows Defender\" rel=\"noopener\">bypassing Windows Defender<\/a> security protections, and then there\u2019s Microsoft\u2019s own decisions to deal with. The <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/02\/03\/microsofts-surprise-decision-removes-privacy-protection-in-25-days\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/02\/03\/microsofts-surprise-decision-removes-privacy-protection-in-25-days\/\" target=\"_self\" aria-label=\"deletion of VPN\" rel=\"noopener\">deletion of VPN<\/a> provision Windows Defender users and, much more seriously, the <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/01\/06\/new-windows-10-cyberattack-warning-as-millions-face-security-oblivion\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/01\/06\/new-windows-10-cyberattack-warning-as-millions-face-security-oblivion\/\" target=\"_self\" aria-label=\"deletion of security support\" rel=\"noopener\">deletion of security support<\/a> for Windows 10 users. As an aside, you can still <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/01\/06\/new-windows-10-cyberattack-warning-as-millions-face-security-oblivion\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/01\/06\/new-windows-10-cyberattack-warning-as-millions-face-security-oblivion\/\" target=\"_self\" aria-label=\"get Windows 11 for free\" rel=\"noopener\">get Windows 11 for free<\/a>, if you are quick. The latest and somewhat confusing situation of Microsoft\u2019s making has come about as Windows users noticed a mysterious new folder after the most recent security update. A folder with no explanation and one which, now, Microsoft has warned a billion Windows users they must not delete.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/04\/01\/google-warns-of-october-3-gmail-account-deletion---how-to-keep-yours\/\" target=\"_blank\" aria-label=\"Google Warns Of October 3 Gmail Account Deletion \u2014 How To Keep Yours\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/04\/01\/google-warns-of-october-3-gmail-account-deletion---how-to-keep-yours\/\">ForbesGoogle Warns Of October 3 Gmail Account Deletion \u2014 How To Keep YoursBy Davey Winder<\/a><br \/>\nDo Not Delete This Mysterious New Windows Folder<\/p>\n<p>As part of the April 8 Patch Tuesday security updates, Microsoft included a fix for CVE-2025-21204. This vulnerability in the critical Windows Update Stack, which is responsible for the management of Windows updates, no less, could lead to an attacker to elevate privileges locally. Something that the <a class=\"color-link\" href=\"https:\/\/securityvulnerability.io\/vulnerability\/CVE-2025-21204\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/securityvulnerability.io\/vulnerability\/CVE-2025-21204\" aria-label=\"experts at SecurityVulnerability.io\">experts at SecurityVulnerability.io<\/a> described as posing \u201ca significant risk to organizations, as the compromised systems could allow attackers to execute unauthorized actions, potentially undermining the integrity and security of sensitive information and system operations.\u201d I won\u2019t bore you with the technicalities of link resolution process manipulation that could enable hackers to access files and execute commands; just know it\u2019s pretty darn serious. Which is why Microsoft fixed it, and that\u2019s a good thing.<\/p>\n<p>The way that Microsoft fixed it, however, is not so good. A lack of transparency is a particular bugbear of mine when it comes to anything security-related, and this vulnerability patch is no exception. The problem is that Microsoft created a new and empty folder with the security update, the appearance of which led to a totally understandable debate in tech forums and on Reddit as well as other social media platforms. What was this \u201cinetpub\u201d folder, how did it get there, is it dangerous, is Microsoft using it to collect data, and should I delete it?<\/p>\n<p>According to a new Microsoft security advisory update, the answer to the last of these questions is a resounding no. Windows users must not delete the inetpub folder, Microsoft warned.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/04\/01\/microsoft-teams-users-exploited-in-sophisticated-multi-stage-ai-attack\/\" target=\"_blank\" aria-label=\"Microsoft Teams Users Exploited In Sophisticated Multi-Stage AI Attack\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/04\/01\/microsoft-teams-users-exploited-in-sophisticated-multi-stage-ai-attack\/\">ForbesMicrosoft Teams Users Exploited In Sophisticated Multi-Stage AI AttackBy Davey Winder<\/a><\/p>\n<p>Microsoft Confirms Reason For New Windows Folder<\/p>\n<p>An April 10 update to Microsoft\u2019s security advisory concerning CVE-2025-21204, entitled \u201c<a class=\"color-link\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-21204 \" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-21204\" aria-label=\"Windows Process Activation Elevation of Privilege Vulnerability\">Windows Process Activation Elevation of Privilege Vulnerability<\/a>,\u201dconfirmed that \u201cafter installing the updates listed in the Security Updates table for your operating system, a new %systemdrive%\\inetpub folder will be created on your device.\u201d<\/p>\n<p class=\"color-body light-text\" role=\"button\">Microsoft Security Advisory<\/p>\n<p>Microsoft<\/p>\n<p>Microsoft went on to say that the folder installation was \u201cpart of changes that increase protection\u201d but failed to explain precisely how. What I do know is that the inetpub folder itself usually comes as part of the Internet Information Services web server platform, enabled using Windows Features, but this update has dropped it whether the user has IIS installed or not. More transparency is required, methinks, although not at the expense of tipping off potential attackers as to how the mitigation works, of course.<\/p>\n<p>What I can say, however, is that as a security wonk, I strongly urge all Windows users to follow Microsoft\u2019s advice: \u201cThis folder should not be deleted regardless of whether Internet Information Services (IIS) is active on the target device.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/04\/01\/infostealer-infects-1-million-windows-devices-via-discord-dropbox-github\/\" target=\"_blank\" aria-label=\"Infostealer Infects 1 Million Windows Devices Via Discord, Dropbox, GitHub\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/04\/01\/infostealer-infects-1-million-windows-devices-via-discord-dropbox-github\/\">ForbesInfostealer Infects 1 Million Windows Devices Via Discord, Dropbox, GitHubBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Do not delete this Windows update folder, Microsoft warns. NurPhoto via Getty Images Windows users have a lot&hellip;\n","protected":false},"author":2,"featured_media":17526,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[11738,11735,507,53,16,15,11737,2897,2898,11734,11733,11736,11732],"class_list":{"0":"post-17525","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-cve-2025-21204","9":"tag-inetpub","10":"tag-microsoft","11":"tag-technology","12":"tag-uk","13":"tag-united-kingdom","14":"tag-what-does-this-windows-folder-do","15":"tag-windows-10","16":"tag-windows-11","17":"tag-windows-security","18":"tag-windows-security-update","19":"tag-windows-security-warning","20":"tag-windows-update-warning"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/114332783116875339","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/17525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=17525"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/17525\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/17526"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=17525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=17525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=17525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}