Accessing clipboard from the lock screen in Windows 10 #2

#UPDATE#
This issue is fixed in the Windows 10 1803 versions and newer.

 

I received a lot of positive feedback on my previous post on accessing the clipboard from the lock screen using the wireless password field.

Just out of curiosity I tried other combinations on doing the same thing, and I found out another cool trick to do the same using the Narrator feature in Windows.
You heard me (#LOL – Narrator is the component that reads stuff out loud) I did the same with Narrator. So, you are probably wondering how I did it using the Narrator. It is shown in the following video:

I also tried to «fuzz» the different fields to see if it is possible to break out of the Narrator application. I was not able to find any method.
Well, hope you enjoyed it and I hope Microsoft does something about this in the future. A quick fix to disable the narrator is to change the ACL on the Narrator.exe and deny read and execute to everyone. I have not found a Group Policy settings that disables this yet. I will update this post if I do.

Hope you enjoyed this post and find this exciting as I do. (I am such a geek)

Update 27.01.2017:
A good point from Papagon in the comments. You can also change the content of the clipboard using CTRL+C.

11 thoughts on “Accessing clipboard from the lock screen in Windows 10 #2

  1. Hi,
    Thanks for sharing this trick.
    From my point of view, this new method is more dangerous than using the wireless password field, because you can now change the clipboard content, simply with ctrl c on the narrator command search field.
    By changing the content, you can imagine other attacks scenarios…

    Like

  2. Nice find! And hard to believe MS is downplaying this.
    Also (shameless plug!) I just released an update to my ClipTTL system tool to instantly clear the clipboard when the session lock is detected.

    Like

  3. Why not just set up a scheduled task to clear the clipboard at logoff?

    Program/Script: C:WindowsSystem32cmd.exe
    Arguments: /c “echo off | clip”

    Like

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.