HomeSecurityWindows 7 and Server 2008 zero-day flaw receives free patch

Windows 7 and Server 2008 zero-day flaw gets free patch

A local privilege escalation (LPE) vulnerability affecting all Windows 7 and Server 2008 R2 devices received a free and temporary fix today via the 0patch platform.

The zero-day flaw affects all affected devices enrolled in Microsoft's Extended Security Updates (ESU) program, whether or not they are eligible until the company releases its own security updates to ESU customers.

Windows 7 Server 2008

0patch's free patch targets Windows 7 and Server 2008 R2 computers without ESU (updated January 2020) and those with ESU (updated November 2020).

Currently, only small and medium-sized businesses or organizations with volume-licensing agreements can obtain an ESU license until January 2023.

From registry misconfiguration to zero-day

The LPE vulnerability stems from the misconfiguration of two registry keys and allows local attackers to elevate privileges on any fully updated Windows 7 and Server 2008 R2 system.

It was discovered by security researcher Clément Labro, who published his research earlier this month, reporting how unsafe permissions on the registry keys HKLM\SYSTEM\CurrentControlSet\Services\Dnscache and HKLM\SYSTEM\CurrentControlSet\Services\RpcEptMapper allow attackers to trick the RPC Endpoint Mapper service into loading malicious DLLs.

This allows them to gain arbitrary code execution within the Windows Management Instrumentation (WMI) service running with LOCAL SYSTEM privileges.

"At this point, if you're still using Windows 7/Server 2008 R2 without first properly isolating those machines on the network , then preventing an attacker from gaining SYSTEM privileges is probably the least of your concerns," Labro said.

Free micropatch for all affected Windows systems

0patch micropatches are code sent via the 0patch platform to Windows clients to fix security issues in real time and are applied to running processes without requiring a system restart

This micropatch is available for free to everyone until Microsoft releases an official fix for the zero-day.

The micropatch “sabotages performance monitoring functions for the two affected services, Dnsclient and RpcEptMapper,” 0patch reports.

“In case performance for these services, micropatch can be temporarily disabled,” Kolsek added.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS