A free micropatch that fixes a local privilege escalation (LPE) vulnerability in Microsoft's Windows PsExec management tool is now available via the 0patch platform.

The PsExec tool allows system administrators to execute programs on remote systems. The PsExec tool is also integrated and used by enterprise tools to remotely launch executables on other computers.
This PsExec zero-day is caused by a named pipe hijacking vulnerability (also known as named pipe squatting) that allows attackers to trick PsExec into reopening a maliciously crafted "named pipe" and granting it local system privileges.
After the successful exploit of the flaw, threat actors will be able to execute arbitrary processes as Local System, which allows them to effectively take over the use of the machine.
Affects PsExec versions released over the past 14 years
Malware researcher David Wells discovered the vulnerability and publicly disclosed it on December 9, 2020, 90 days after Microsoft updated it and failed to fix the bug
While researching the vulnerability and creating a proof-of-concept, Wells was able to confirm that the zero-day vulnerability affects multiple versions of Windows from Windows XP to Windows 10.
It was also found to affect multiple PsExec versions, starting with v1.72 released in 2006 and ending with PsExec v2.2, the last version released four years ago, meaning the zero-day vulnerability affects all PsExec versions released in the last 14 years.
The micropatch applies only to the latest version of PsExec
Kolsek says that the free micropatch released today is delivered in memory and does not require a system reboot .
It applies to the latest 32-bit and 64-bit PsExec version, but may be ported to older PsExec versions depending on user, as Kolsek wrote earlier today.
Information source: bleepingcomputer.com
