HomeinetNew Windows 0day on Twitter

New Windows 0day on Twitter

A security researcher has revealed a new Windows 0day on Twitter. It's the second in two months. The researcher, who goes by the online alias SandboxEscaper, also published the PoC on GitHub.

It is the second Windows 0day that affects Microsoft Data Sharing (dssvc.dll), a local service that provides data management between applications.0day

According to several security experts who analyzed the PoC, an attacker can use the 0day to escalate their privileges on systems they already have access to.

The PoC, in particular, was coded to delete files that a user would normally need administrator privileges to do. With the right modifications, other actions could be taken, experts believe. The 0day only affects the latest versions of the Windows operating system. This means that all versions of Windows 10, Server 2016 and the new Server 2019 are at risk, according to several security experts who confirmed the PoC.

According to Will Dormann of CERT/CC, this is because the “data sharing service (dssvc.dll) does not appear to exist in Windows 8.1 and earlier versions.”

Today's 0day is almost identical to the first one that SandboxEscaper posted on Twitter in late August. SandboxEscaper claims that the second security flaw is just as useful to attackers as the first. The researcher believes that malware developers could use it to delete files or DLLs and replace them with malicious versions.

Just like after the first 0day, 0Patch released a fix until Microsoft released an official fix. The company seems to be currently trying to create a “micro-patch” for all affected versions of Windows.

__________________

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS