Free unofficial updates for a new zero-day vulnerability in Windows called EventLogCrasher, which allows attackers to remotely crash the Event Log service on devices within the same Windows domain.
See also: Google Chrome: Emergency update for zero-day vulnerability

This zero-day vulnerability affects all versions of Windows, from Windows 7 to the latest Windows 11 , and from Server 2008 R2 to Server 2022.
EventLogCrasher was discovered and reported to the Microsoft Security Response Center team by a security researcher with the alias Florian. Microsoft classifies it as unmaintainable and labels it as a duplicate of the 2022 bug (Florian also published a PoC last week).
While Microsoft did not provide further details about the 2022 vulnerability, software company Varonis disclosed a similar vulnerability called “LogCrusher” (which is still awaiting a fix) that can be exploited by any user in the domain to remotely bring down the service on Windows machines across the domain.
To exploit the vulnerability in the default Windows Firewall settings, attackers need network connectivity to the target device and valid credentials (even with low privileges).
See also: Apple fixes zero-day vulnerabilities in older iPhones
This way, they can always bring down the Event Log service locally and on all computers in the same domain, including domain controllers, thereby ensuring that their malicious activity will no longer be recorded in the Windows Event Log.
According to Florian, the crash occurs in wevtsvc!VerifyUnicodeString when an attacker sends a malformed UNICODE_STRING object to the ElfrRegisterEventSourceW method , which is exposed by the RPC-based remote event logging protocol.

Fortunately, security and system events are stored in memory and will be added to the event logs after the event log service is available again.
“So far, we have discovered that a low-privileged attacker can bring down the event logging service on both the local computer and any other Windows computer on the network to which they can authenticate. In a Windows domain, this means all computers in the domain, including domain controllers,” said 0patch co-founder Mitja Kolsek.
The 0patch service has released unofficial patches for most affected versions of Windows, available for free until Microsoft releases official security updates to address the zero-day EventLogCrasher.
See also: Apple fixes zero-day that allows attacks on iPhone/iPad
What are the techniques for dealing with Zero-Day attacks?
The first technique that can be used to combat Zero-Day attacks is software updating and auditing. This means that software must be updated regularly so that it can address any vulnerabilities that an attacker might exploit.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Another technique is to use intrusion detection tools (IDS) and intrusion prevention systems (IPS). These tools can detect and prevent zero-day attacks by analyzing network traffic and detecting any unusual behavior.
Using anti-malware software is another technique that can be used. One of the most effective ways to combat Zero-Day attacks is to use anti-virus and anti-malware software that provides real-time protection and has the ability to update automatically.
Implementing the principle of least privilege (PoLP) can also help protect against Zero-Day attacks, as it limits users' access to only what they need to perform their tasks.
Source: bleepingcomputer
