Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

Latest Rufus release fixes side-loading vulnerability

Posted on April 9, 2025April 9, 2025 by Martin Brinkmann

Rufus, one of my favorite open source tools, is now available in a new version. Rufus 4.7 is a security release that includes new features and non-security fixes.

The developer fixed a side-loading vulnerability in the application that allowed an attacker to load a malicious DLL with escalated privileges.

For this to work, the attacker had to plant the malicious DLL file into the same directory as the Rufus executable. The impact seems low, but it is still good that the issue got fixed.

Here is the info provided on the Rufus Security forum:

A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an attacker loading and executing a malicious DLL with escalated privileges (since the executable has been granted higher privileges during the time of launch) due to the ability to inject a malicious cfgmgr32.dll in the same directory as the executable and have it side load automatically. Versions 4.7 and later are not affected by this vulnerability.

So, it is recommended to update Rufus to the latest version to patch the issue.

Note that the internal update finder may not find the update yet. You can download it manually from the project’s GitHub repository in the meantime.

As far as other features are concerned, there are a handful:

  • Ability to detect and download updated DBXs from the official UEFI repository.
  • Support for ztsd compression for disk images added.
  • Exclusion feature in Settings to “ignore disk with a specific GPT GUID”.

There are also some fixes included, which you find listed here.

Tags:
Category: Security & Privacy

Post navigation

← Arc Browser: and then there was Dia
Microsoft releases out-of-band Windows updates, but you likely don’t need them →

1 thought on “Latest Rufus release fixes side-loading vulnerability”

  1. VioletMoon says:
    April 9, 2025 at 9:00 pm

    Rufus 4.6 never did work for me on Windows 11 24H2; I always received a “USB is in use by another process; please close and try again.” Apparently, the program gaining access to the USB was explorer.exe.

    When I checked online for a solution, I did find numerous others had the same problem years ago and the developer claimed the issue wasn’t with Rufus, but something else.

    One list of fixes, none of which worked for me.

    https://www.minitool.com/news/rufus-access-to-device-denied.html

    Tried again with a quick .iso download of Windows; worked fine. Guess I can keep it as an emergency “repair” install USB.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • October 12, 2025 by Martin Brinkmann Windows 11, Version 23H2 Home and Pro will stop getting updates starting next month
  • October 10, 2025 by Martin Brinkmann Test your PC's Windows 11 compatibility with free WhyNotWin11
  • October 7, 2025 by Martin Brinkmann Microsoft breaks more Windows 11 local account creation options
  • October 5, 2025 by Martin Brinkmann Firefox 143.0.4 fixes Google connection problems
  • October 3, 2025 by Martin Brinkmann You can now try Perplexity's Comet AI browser for free

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2025 Chipp.in Tech News and Reviews