Serious flaw discovered in Windows Vista's Explorer


Recommended Posts

For anyone who is interested, here are the reproduction steps:

  1. Click on Start, and then click on Documents.
  2. In the Search entry box, type "NOT Shortcut" (without the quotes).
  3. Click on the "Save Search" button and save the search query as "Search Test".

I've removed the rest of the post due to the un-necessary amount of spam that I have received in the past 24 hours.

Edited by iCeFuSiOn

Very close to being blogspam. This is a serious flaw? Worst case scenario is the explorer process crashes and restarts without even restarting the OS. It may have taken down XP, but Vista just restarts the process and it's fine. Should MS fix it...of course. Is it a major flaw that's going to have any real impact, no. MS can fix it easily with a patch. Nice try to fabricate an issue out of nothing though. In fact demonstrates how Vista is much more robust against these sort of glitches than XP ever was.

Uhh... so you're searching for something that is NOT a shortcut? ie: pretty much everything? What do you expect to happen? :laugh:

If you're trying to search for documents only and the explorer brings back a list of shortcuts as well, NOT Shortcut will hide them. What it ISN'T supposed to do is crash the shell. This was bugged for SP1 and was marked as "won't fix".

If you're trying to search for documents only and the explorer brings back a list of shortcuts as well, NOT Shortcut will hide them. What it ISN'T supposed to do is crash the shell. This was bugged for SP1 and was marked as "won't fix".

Right, but usually you have something like "<some doc title> NOT Shortcut" and that doesn't crash, in fact it works exactly as expected. But placing just "NOT Shortcut" without any other filter does crash it instantly. So, yea, it crashes if that is your intention, but really this isn't much of an issue. Although it should probably be fixed, it's really not a big deal. Either way, I'm sure a patch will be released eventually. Probably after SP1, though.

I won't call this a serious but probably an unfortunate bug. Vista has other issues that are more important that this. Such as slow copying speeds and folder view thingy.

If you're trying to search for documents only and the explorer brings back a list of shortcuts as well, NOT Shortcut will hide them. What it ISN'T supposed to do is crash the shell. This was bugged for SP1 and was marked as "won't fix".

can use kind:document ? or just remove appdata folder from your index locations...that is what I do.

:rofl:

And to think I actually expected to read about a serious flaw...

Good grief, even in XP bringing back a crashed explorer is as easy as bringing up the task manager and doing a File >> Run explorer.exe

Apparently Vista does that all for you. Hardly anything to bash Vista for.

Not to mention that nobody out there even searches for "NOT Shortcut" by itself (given by the fact that it took over a year to even find this flaw...)

-Spenser

Why are we the source?

heh. we say they are the sourc they say it's us. A nice vicious cycle of sourcing.

Anyway it doesn't seem overly serious but it definitely should be fixed. I doubt it will kill anyone but it's blemishes like this that day in day out tarnish Vista's image. It's not the most pressing issue by all means, but still should be looked at.

We can only curse at things like this because WinFS would have certainly avoided such problems.

*sigh*

:ike:

Go look up WinFS and come back and give us a report on it. WinFS is not what you think it is. ;)

Why are we the source?

He changed it. Here's the original link: http://www.windows-now.com/blogs/kmkenney/...plorer-bug.aspx

As I said... This post is total flame bait and some people have already bitten the hook. ;)

wow the thread title and original post really tries to make this sound like a big deal. unfortunately for them it really isn't i'm sure it will be fixed but i wonder how many times people actually search for NOT shortcut. and anyway explorer restarts quickly really not much of a problem. if this is a seriuos flaw i would like to see how the author would describe all the problems that device drivers are causing in vista.

At a time where everyone is anxiously awaiting the upcoming service pack for Windows Vista (and while others flock back to Windows XP in droves), yet another flaw in the Windows Vista operating system has been discovered that can bring the Windows shell ("Windows Explorer") to its knees within 20 seconds. Even worse, this issue occurs under every day usage of the operating system if you use the Search function regularly with boolean search operators.

  1. Click on Start, and then click on Documents.
  2. In the Search entry box, type "NOT Shortcut" (without the quotes).
  3. Click on the "Save Search" button and save the search query as "Search Test".

This has been confirmed as a flaw in Windows Vista (all editions) and Windows Vista 64-bit (all editions), and even worse, the issue still occurs on the latest release candidate for Service Pack 1, and has been marked as "will not be fixed". The bigger question is, will Microsoft step up to the plate and fix this issue or will they let it pass on by while they work heavily on Windows "7", ignoring the fact that Windows Vista still has flaws and inconsistancies that are seeing larger companies hold back deployment until 2009 or even skip Vista?

Source of instructions to reproduce issue: ActiveWin.com

So from this we can learn a few things.

1) Vista must be in better shape and more on track and stable than the anti-Vista zealots would like for people to believe if it has taken a year for something like this to be classified as a serious flaw. For people that can think for themselves, this is the best pro-Vista post in history...

2) The person that found this flaw is a bit scary to expect this to be a valid search, especially so important to save it as a Search Folder. But hey, everyone to their own thing, so I'm over the scary part.

3) The person that posted this thinks MS is heavily working on Windows 7. Well it is true MS's NT cycle always starts at the end of a product release, so we can assume they are working on Windows 7. However, it is time for the idiots that keep running around thinking MinWin is Windows 7 or any different than the 'tight' kernel that is already in Vista and all previous versions of NT to wake up and watch the presentation or talk to someone at Microsoft for an accurate source on the subject. Windows 7 is not very active yet, and its kernel technology is the same as Vista, and it is scary that after 15 years of NT, people don't yet realize that the NT kernel is in fact very tight and small when you remove the API interface layers. (NT is a light API interface hybrid kernel technology) - This is why MinWin was a basic recompile of Vista kernel with the external APIs turned off, PERIOD.

4) Let's hope the person that found this fatal flaw doesn't do a nested search in a search that is recursive. They will really be mad at Windows then... Which points out another good thing about this bug, instead of dragging the system to a grind in an endless loop, or even choking, Vista just restarts Explorer and goes on its way. PS It will only restart the 'Folder Window' and not fully restart Explorer if you have "Launch folder windows in a separate process" (PS Which is handy to turn on)

Now for the unknown:

There is already an easy fix for this, pick a different freaking syntax, Vista has the most diverse search engine in OS history, with the most extensive set of search options including natural language and strict syntax as the user chooses.

Here is the 'fix' or way to perform the search effortlessly without killing Explorer if you really want to do this search:

NOT (ext:lnk OR ext:url)

-This also excludes Internet shortcuts, and is more accurate as you don't get folders in the mix of results.

NOT ext:lnk

-This is if you only want to exclude plain shortcuts and not Internet shortcuts, and again works better as it doesn't mix folders in the results.

You could also do:

-(ext:lnk OR ext:url)

or

-ext:lnk

Get the idea here? There are numerous ways to get the same results that don't involve killing Explorer

Now with that MAJOR flaw out of the way, this would be a good time to remind people that the search features in Vista are pretty powerful in doing more than just searching for items.

Look up a tool called Start++ from brandontools.com - (it is handy) and from it you can get an idea of how powerful the searching system is and how it can be extended in basic shell and commandline usage even. (Most people don't realize you can get search results in a CMD prompt, or from within their applications.)

Also for people doing more than causal searches, take a minute and read some up on some of the syntax options Vista offers and see why it makes Leopard and even Google Desktop Search look like toys.

This is a good reference page to begin with for the basics of advanced searching in Vista:

http://search.msn.com/docs/toolbar.aspx?t=...earchSyntax.htm

So from this we can learn a few things.

1) Vista must be in better shape and more on track and stable than the anti-Vista zealots would like for people to believe if it has taken a year for something like this to be classified as a serious flaw. For people that can think for themselves, this is the best pro-Vista post in history...

2) The person that found this flaw is a bit scary to expect this to be a valid search, especially so important to save it as a Search Folder. But hey, everyone to their own thing, so I'm over the scary part.

3) The person that posted this thinks MS is heavily working on Windows 7. Well it is true MS's NT cycle always starts at the end of a product release, so we can assume they are working on Windows 7. However, it is time for the idiots that keep running around thinking MinWin is Windows 7 or any different than the 'tight' kernel that is already in Vista and all previous versions of NT to wake up and watch the presentation or talk to someone at Microsoft for an accurate source on the subject. Windows 7 is not very active yet, and its kernel technology is the same as Vista, and it is scary that after 15 years of NT, people don't yet realize that the NT kernel is in fact very tight and small when you remove the API interface layers. (NT is a light API interface hybrid kernel technology) - This is why MinWin was a basic recompile of Vista kernel with the external APIs turned off, PERIOD.

4) Let's hope the person that found this fatal flaw doesn't do a nested search in a search that is recursive. They will really be mad at Windows then... Which points out another good thing about this bug, instead of dragging the system to a grind in an endless loop, or even choking, Vista just restarts Explorer and goes on its way. PS It will only restart the 'Folder Window' and not fully restart Explorer if you have "Launch folder windows in a separate process" (PS Which is handy to turn on)

Now for the unknown:

There is already an easy fix for this, pick a different freaking syntax, Vista has the most diverse search engine in OS history, with the most extensive set of search options including natural language and strict syntax as the user chooses.

Here is the 'fix' or way to perform the search effortlessly without killing Explorer if you really want to do this search:

NOT (ext:lnk OR ext:url)

-This also excludes Internet shortcuts, and is more accurate as you don't get folders in the mix of results.

NOT ext:lnk

-This is if you only want to exclude plain shortcuts and not Internet shortcuts, and again works better as it doesn't mix folders in the results.

You could also do:

-(ext:lnk OR ext:url)

or

-ext:lnk

Get the idea here? There are numerous ways to get the same results that don't involve killing Explorer

Now with that MAJOR flaw out of the way, this would be a good time to remind people that the search features in Vista are pretty powerful in doing more than just searching for items.

Look up a tool called Start++ from brandontools.com - (it is handy) and from it you can get an idea of how powerful the searching system is and how it can be extended in basic shell and commandline usage even. (Most people don't realize you can get search results in a CMD prompt, or from within their applications.)

Also for people doing more than causal searches, take a minute and read some up on some of the syntax options Vista offers and see why it makes Leopard and even Google Desktop Search look like toys.

This is a good reference page to begin with for the basics of advanced searching in Vista:

http://search.msn.com/docs/toolbar.aspx?t=...earchSyntax.htm

Actually, about the MinWin thing, the Core effort (which is the sliced off APIs) used to be called MinWin, but there's another effort to remake the kernel called MinWin and that does involve changing the kernel architecture.

The current slimmed-down kernel need the entire source tree to be built to build the kernel, because even though it doesn't call the APIs above, they're still needed to complete dependencies.

The new MinWin will enable the kernel to be built alone, or parts of the system, which helps in the layering, upkeep and testing of the OS.

Other than that, very informative post :)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Amazon Prime Day slashes Samsung's newest Galaxy Watch Ultra by 45 percent by Karthik Mudaliar Samsung’s flagship Android smartwatch has received one of its steepest Prime Day cuts. Amazon has dropped the 2025 Samsung Galaxy Watch Ultra in Titanium Blue to $357.24, saving buyers around $292 from its $649.99 list price. That's a 45 percent discount (purchase link below). The 47mm Galaxy Watch Ultra uses a titanium casing and a 1.5-inch Super AMOLED display with a resolution of 480 x 480 and peak brightness of 3,000 nits. It includes LTE connectivity, Bluetooth 5.3, Wi-Fi, NFC, and dual-frequency L1+L5 GPS for more accurate outdoor route tracking. The 2025 model has 64GB of storage, a 590mAh battery, sapphire crystal glass, 10ATM water resistance, IP68 protection, and MIL-STD-810H durability testing. Its health and fitness tools include heart rate monitoring, sleep coaching, Energy Score, Running Coach, body composition analysis, temperature sensing, and ECG support, where available. This model is best suited to Android users who regularly run, hike, cycle, or train outdoors and want cellular access without carrying a phone. The larger battery, rugged construction, bright display, and dedicated Quick Button also make it a stronger option than Samsung’s regular Galaxy Watch models for extended workouts and demanding environments. Grab the Titanium Blue Galaxy Watch Ultra before the Prime Day price resets: Samsung Galaxy Watch Ultra (2025) [Sold and Shipped by Amazon] Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Google begins rolling out its post-Epic Play Store billing model next week by Karthik Mudaliar Google has confirmed that its redesigned Play Store billing and fee structure will take effect on June 30, 2026, in the United States, the United Kingdom, and the European Economic Area. The changes will let eligible developers offer their own payment systems or send users to an external website for purchases, while separating Google’s platform service fee from the cost of using Google Play Billing. The rollout puts concrete dates and detailed rate cards behind the broader Android policy overhaul Google announced in March. That announcement followed a proposed settlement with Epic Games intended to resolve their long-running disputes over app distribution and payments, although the U.S. portion of the agreement still requires court approval. Under the new billing choice program, developers selling digital content or services can display an alternative payment option alongside Google Play Billing. They may also direct users to their own websites to complete a purchase. Developers can use Google’s standard payment-choice screen or design one that complies with the company’s user-interface rules. Choosing another payment processor does not eliminate Google’s cut altogether. The company will continue charging a service fee for transactions associated with apps distributed through Google Play, regardless of whether payment is handled by Google, an alternative provider, or a developer’s website. Google argues that this fee covers the value and infrastructure provided by Android and the Play Store. For developers earning up to $1 million annually, the service fee will generally be 10 percent. That rate also applies to auto-renewing subscriptions. When Google Play Billing is used in the U.S., U.K., or EEA, Google will add a separate 5 percent billing fee, and developers processing payments elsewhere will not pay that additional charge. This means Google’s familiar flat 30 percent commission is disappearing, but developers will not necessarily see a dramatic reduction on every transaction. An in-app purchase from an existing user processed through Google Play Billing can still reach a combined 30 percent. The biggest savings are likely to come from subscriptions, smaller developers covered by the $1 million tier, and companies able to move customers to their own payment infrastructure. Google is also offering lower rates through its Apps Experience and revamped Games Level Up programs. Apps and games that satisfy the company’s requirements can qualify for 15 percent service fees on new-install transactions and 20 percent on existing-install transactions. The criteria include performance and reliability standards, support for additional Android device categories, and selected platform features. Those program rates are scheduled to become available in the initial markets and Australia on September 30. For consumers, the immediate effect will depend on whether developers adopt alternative payments and pass any savings on through lower prices. For developers, however, June 30 begins a more flexible but considerably more complicated Play Store economy in which distribution, billing, install dates, revenue thresholds, and program participation can each affect Google’s final cut. Google is also separately developing a Registered App Stores program designed to simplify the installation of qualifying third-party stores. That initiative is expected to arrive with a major Android release later in 2026 and will launch outside the U.S. first. Google says the rest of the world will receive the changes by September 30, 2027, although billing rates for markets outside the US, UK, and EEA have not yet been announced.
    • 38% off a super insane price is still an INSANE price.
    • 1TB Samsung T9 and Samsung 9100 PRO SSDs are now selling at great prices by Fiza Ali Amazon is now offering the 1TB variant of Samsung T9 and Samsung 9100 PRO SSD at great prices with limited-time 38% and 39% discounts, respectively, so you may want to check them out if you have been looking to upgrade your storage solution. The Samsung T9 connects via a USB 3.2 Gen 2x2 (20Gbps) interface and delivers sequential read speeds of up to 2,000MB/s and sequential write speeds of up to 1,950MB/s, making it suitable for transferring large files, backing up data, and handling high-resolution media content. When it comes to the security features, the SSD includes AES 256-bit hardware encryption to help protect sensitive data. Designed for portability, the drive is reportedly resistant to drops from heights of up to 3 metres. Furthermore, it operates within a temperature range of 0°C to 60°C and can be stored at temperatures between -40°C and 85°C. Samsung Magician Software is included for drive management, firmware updates, performance optimisation, and health monitoring. Finally, the T9 is certified to multiple international standards, including CE, FCC, UL, UKCA, and RoHS 2 compliance, and is backed by a five-year limited warranty as well. 1TB Samsung T9 SSD: $179.99 (Amazon US) - 38% off The Samsung 9100 PRO uses the M.2 2280 form factor and connects through a PCIe 5.0 x4 interface with NVMe 2.0 support. Built with Samsung V-NAND TLC flash memory, an in-house controller, and 1GB of low-power DDR4X cache memory, the 9100 PRO is engineered for high-performance computing and gaming workloads. Furthermore, the SSD delivers sequential read speeds of up to 14,700MB/s and sequential write speeds of up to 13,300MB/s. Random performance is rated at up to 1,850,000 IOPS for reads and up to 2,600,000 IOPS for writes, depending on system hardware and configuration. The drive supports TRIM, S.M.A.R.T monitoring, automatic garbage collection, and device sleep mode to help maintain performance and efficiency over time. In terms of security features, it includes AES 256-bit encryption, TCG Opal support, and IEEE 1667 compliance. The 9100 PRO operates within a temperature range of 0°C to 70°C, is rated for 1.5 million hours MTBF, and can reportedly withstand shocks of up to 1,500G for 0.5 milliseconds. Finally, Samsung Magician Software is also included for firmware updates, performance monitoring, drive management, and optimisation. 1TB Samsung 9100 PRO SSD: $206.99 (Amazon US) - 39% off Alternatively, you can also check out other SSD deals here. Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Dedicated
      Scoobystu earned a badge
      Dedicated
    • First Post
      Tom Schmidt earned a badge
      First Post
    • One Month Later
      D0nn13 earned a badge
      One Month Later
    • Rookie
      +ChiefOfNeo went up a rank
      Rookie
    • One Year In
      Tom Schmidt earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      463
    2. 2
      +Edouard
      177
    3. 3
      PsYcHoKiLLa
      124
    4. 4
      Michael Scrip
      81
    5. 5
      Xenon
      76
  • Tell a friend

    Love Neowin? Tell a friend!