ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Hacker Discloses Second Zero

criticalExploit / PoCimportance 60CVE-2019-0841

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0841
Local Privilege Escalation via Hard-Link Flaw in Windows AppX Deployment Service

CVE-2019-0841 is a local privilege escalation flaw in the Windows AppX Deployment Service (AppXSVC), which handles deployment of packaged (AppX) applications. The service improperly handles hard links (CWE-59), letting a local attacker manipulate hard links so that AppXSVC performs file operations in protected locations with elevated rights. A successful exploit allows the attacker to run processes in an elevated context — effectively administrative/SYSTEM privileges — which ransomware operators have used in chained attacks. Any unpatched Microsoft Windows system is potentially affected; the available data lists only 'Microsoft Windows' without specific version ranges, so defenders should consult Microsoft's advisory for exact affected releases. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, and EPSS assigns a 41.4% probability of exploitation within 30 days (99th percentile), although no public proof-of-concept is catalogued.

Do: Apply Microsoft's Windows cumulative updates per vendor instructions as the KEV required action, prioritizing systems where users can log on locally, since exploitation requires local access; the fix shipped in Microsoft's April 2019 security release, so confirm no hosts remain on older builds. Because ransomware operators chain this local privilege escalation, verify patch status across the estate with your inventory tooling and monitor for unexpected elevation or hard-link manipulation on AppXSVC as interim risk reduction.

7.841% KEV ransomware PoC ×2
  • Microsoft Windows
masshundreds of millions of Windows endpoints potentially in scope (Windows runs on 1B+ active devices, ~70% desktop share), limited to unpatched systems
Full article394 words · extracted from thehackernews.com · click to collapse

An anonymous security researcher going by the name of SandboxEscaper today publicly shared a second zero-day exploit that can be used to bypass a recently patched elevation of privilege vulnerability in the Microsoft Windows operating system.

SandboxEscaper is known for publicly dropping zero-day exploits for unpatched Windows vulnerabilities. In the past year, the hacker has disclosed over half a dozen zero-day vulnerabilities in Windows OS without actually bothering to make Microsoft aware of the issues first.

Just two weeks ago, the hacker disclosed four new Windows exploits, one of which was an exploit that could allow attackers to bypass a patched elevation of privilege vulnerability (CVE-2019-0841) in Windows that existed when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.

Now, the hacker claims to have found a new way to bypass Microsoft security patch for the same vulnerability, allowing a specially crafted malicious application to escalate its privileges and take complete control of patched Windows machine.

Dubbed ByeBear, as shown in the video demonstration, the new exploit abuses Microsoft Edge browser to write discretionary access control list (DACL) as SYSTEM privilege.

"It's going to increase the thread priority to increase our odds of winning the race condition that this exploits. If your VM freezes, it means you either have 1 core or set your VM to have multiple processors instead of multiple cores... which will also cause it to lock up," SandboxEscaper explains.

"This bug is most definitely not restricted to the edge. This will be triggered with other packages too. So you can definitely figure out a way to trigger this bug silently without having edge pop up. Or you could probably minimize edge as soon as it launches and closes it as soon as the bug completes."

"I think it will also trigger by just launching edge once, but sometimes you may have to wait for a little. I didn't do extensive testing...found this bug and quickly wrote up a PoC, took me like 2 hours total, finding LPEs is easy."

The next patch Tuesday updates from Microsoft are due on 11th June, and it would be interesting to see if the company would acknowledge four previous exploits and the new one and release security fixes to address them.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2019/06/windows-eop-exploit.html