HomeSecurityEventLogCrasher: New zero-day receives unofficial patch

EventLogCrasher: New zero-day receives unofficial patch

Free unofficial updates for a new zero-day vulnerability in Windows called EventLogCrasher, which allows attackers to remotely crash the Event Log service on devices within the same Windows domain.

See also: Google Chrome: Emergency update for zero-day vulnerability

EventLogCrasher

This zero-day vulnerability affects all versions of Windows, from Windows 7 to the latest Windows 11 , and from Server 2008 R2 to Server 2022.

EventLogCrasher was discovered and reported to the Microsoft Security Response Center team by a security researcher with the alias Florian. Microsoft classifies it as unmaintainable and labels it as a duplicate of the 2022 bug (Florian also published a PoC last week).

While Microsoft did not provide further details about the 2022 vulnerability, software company Varonis disclosed a similar vulnerability called “LogCrusher” (which is still awaiting a fix) that can be exploited by any user in the domain to remotely bring down the service on Windows machines across the domain.

To exploit the vulnerability in the default Windows Firewall settings, attackers need network connectivity to the target device and valid credentials (even with low privileges).

See also: Apple fixes zero-day vulnerabilities in older iPhones

This way, they can always bring down the Event Log service locally and on all computers in the same domain, including domain controllers, thereby ensuring that their malicious activity will no longer be recorded in the Windows Event Log.

According to Florian, the crash occurs in wevtsvc!VerifyUnicodeString when an attacker sends a malformed UNICODE_STRING object to the ElfrRegisterEventSourceW method , which is exposed by the RPC-based remote event logging protocol.

zero day

Fortunately, security and system events are stored in memory and will be added to the event logs after the event log service is available again.

“So far, we have discovered that a low-privileged attacker can bring down the event logging service on both the local computer and any other Windows computer on the network to which they can authenticate. In a Windows domain, this means all computers in the domain, including domain controllers,” said 0patch co-founder Mitja Kolsek.

The 0patch service has released unofficial patches for most affected versions of Windows, available for free until Microsoft releases official security updates to address the zero-day EventLogCrasher.

See also: Apple fixes zero-day that allows attacks on iPhone/iPad

What are the techniques for dealing with Zero-Day attacks?

The first technique that can be used to combat Zero-Day attacks is software updating and auditing. This means that software must be updated regularly so that it can address any vulnerabilities that an attacker might exploit.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Another technique is to use intrusion detection tools (IDS) and intrusion prevention systems (IPS). These tools can detect and prevent zero-day attacks by analyzing network traffic and detecting any unusual behavior.

Using anti-malware software is another technique that can be used. One of the most effective ways to combat Zero-Day attacks is to use anti-virus and anti-malware software that provides real-time protection and has the ability to update automatically.

Implementing the principle of least privilege (PoLP) can also help protect against Zero-Day attacks, as it limits users' access to only what they need to perform their tasks.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS