HomeSecurityWindows 10 zero-day that grants administrator privileges is temporarily fixed

Windows 10 zero-day that grants administrator privileges is temporarily fixed

Free unofficial code updates have been released to protect Windows 10 users from a zero‑day vulnerability that allows privilege escalation (LPE) in the Device Management Service affecting Windows 10, version 1809 and newer.

Windows 10

See also: Windows 10 21H2 feature update released: What are the new features?

The security flaw is located in the “Access to work or school” settings and bypasses a patch released by Microsoft in February to address an information disclosure bug, known as CVE-2021-24084.

However, security researcher Abdelhamid Naceri, who also reported the original vulnerability, discovered this month that the flaw that had not been fully patched could also be exploited to gain administrator privileges.

«We confirmed it using the procedure described in this blog post by Raj Chandel combined with Abdelhamid's bug and having the ability to execute code as a local administrator.»

While Microsoft has probably also noticed Naceri's disclosure, the company has not yet fixed this LPE bug, exposing Windows 10 systems that have applied the latest security updates of November 2021 to attacks.

See also: Patch released for RCE exploit in Microsoft Exchange

Fortunately, attackers can exploit the vulnerability only if two very specific conditions are met:

  • System protection must be enabled on drive C and at least one restore point must be created. Whether system protection is enabled or disabled by default depends on various parameters.
  • At least one local administrator account must be enabled on the computer or at least one member of the “Administrators” group must have temporarily stored the credentials.
zero day

Until Microsoft releases security updates to address this issue, micropatching service 0patch has released free and unofficial patches for all affected versions of Windows 10, except Windows 10 21H2:

  • Windows 10 v21H1 (32 & 64 bit) was updated with November 2021 updates
  • Windows 10 v20H2 (32 & 64 bit) was updated with November 2021 updates
  • Windοws 10 v2004 (32 & 64 bit) was updated with November 2021 updates
  • Windows 10 v1909 (32 & 64 bit) was updated with November 2021 updates
  • Windows 10 v1903 (32 & 64 bit) was updated with November 2021 updates
  • Windows 10 v1809 (32 & 64 bit) was updated with May 2021 updates

See also: Malware tries to exploit new Windows Installer zero-day

«Windows servers are not affected, as the vulnerable functionality does not exist there. While some similar diagnostic tools exist on servers, they run under the startup user identity and therefore cannot be used».

To install the unofficial code update on your system, you will need to register a 0patch account and install the 0patch agent. Once you start the service on your device, the updated code version will be applied automatically without requiring a reboot.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS