Microsoft has patched an easily exploitable vulnerability in Windows 10’s Cortana smart assistant. The elevation of privilege vulnerability resides due to Cortana’s failure to adequately check command inputs. An attacker who successfully exploited the vulnerability could execute commands with elevated permissions. Microsoft has classified the flaw as “important” because exploitation requires an attacker to have physical or console access to the targeted system and the system also needs to have Cortana enabled. McAfee recommends users to turn off Cortana on the lock screen in order to prevent such attacks.
Source: https://thehackernews.com/2018/06/cortana-hack-windows-password.html