Month: September 2018

Microsoft fixes the recent ALPC zero-day in time for September 2018 Patch Tuesday

Microsoft fixes the recent ALPC zero-day in time for September 2018 Patch Tuesday

Last week a security researcher known on Twitter as SandboxEscaper decided to go out with a bang by revealing a zero-day effecting Windows operating systems in the form of a tweet rather than submitting a bug report to Microsoft. SandboxEscaper additionally posted a link to a proof-of-concept on Github, just encase anyone doubted the vulnerability.

The zero-day was in-turn verified by US-CERT (kb article here), Microsoft said in a statement to The Register that it would “proactively update impacted devices as soon as possible.”

The zero-day is in Microsoft Windows task scheduler SchRpcSetSecurity This component (or rather the API within it) contains a vulnerability in how it handles Advanced Local Procedure Call (ALPC). That vulnerability in ALPC can then allow an authenticated user to overwrite the contents of a file that should be protected by filesystem ACLs. This in-turn can then be leveraged to gain SYSTEM privileges. This vulnerability was then incorporated into a current malware distribution campaign by the cyber-criminal group known as PowerPool.

Now let’s get to today, Microsoft has released their September installment or patches and this batch contains 62 important fixes with the most noted being the ALPC Zero-Day tracked as CVE-2018-8440.

Currently it is important to note that this vulnerability is being actively used and their is no “official” mitigation, so the only Microsoft approved fix it to apply the patch as soon as possible, if you want the direct download links or links to the relevant KB article then please find them below.

 

Product

Article

Download

Windows 10 for 32-bit Systems 4457132 Security Update
Windows 10 for x64-based Systems 4457132 Security Update
Windows 10 Version 1607 for 32-bit Systems 4457131 Security Update
Windows 10 Version 1607 for x64-based Systems 4457131 Security Update
Windows 10 Version 1703 for 32-bit Systems 4457138 Security Update
Windows 10 Version 1703 for x64-based Systems 4457138 Security Update
Windows 10 Version 1709 for 32-bit Systems 4457142 Security Update
Windows 10 Version 1709 for 64-based Systems 4457142 Security Update
Windows 10 Version 1803 for 32-bit Systems 4457128 Security Update
Windows 10 Version 1803 for x64-based Systems 4457128 Security Update
Windows 7 for 32-bit Systems Service Pack 1 4457144 Monthly Rollup
4457145 Security Only
Windows 7 for x64-based Systems Service Pack 1 4457144 Monthly Rollup
4457145 Security Only
Windows 8.1 for 32-bit systems 4457129 Monthly Rollup
4457143 Security Only
Windows 8.1 for x64-based systems 4457129 Monthly Rollup
4457143 Security Only
Windows RT 8.1 4457129 Monthly Rollup 
Windows Server 2008 for 32-bit Systems Service Pack 2 4458010 Monthly Rollup
4457984 Security Only
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 4458010 Monthly Rollup
4457984 Security Only
Windows Server 2008 for Itanium-Based Systems Service Pack 2 4458010 Monthly Rollup
4457984 Security Only
Windows Server 2008 for x64-based Systems Service Pack 2 4458010 Monthly Rollup
4457984 Security Only
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 4458010 Monthly Rollup
4457984 Security Only
Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 4457144 Monthly Rollup
4457145 Security Only
Windows Server 2008 R2 for x64-based Systems Service Pack 1 4457144 Monthly Rollup
4457145 Security Only
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 4457144 Monthly Rollup
4457145 Security Only
Windows Server 2012 4457135 Monthly Rollup
4457140 Security Only
Windows Server 2012 (Server Core installation) 4457135 Monthly Rollup
4457140 Security Only
Windows Server 2012 R2 4457129 Monthly Rollup
4457143 Security Only
Windows Server 2012 R2 (Server Core installation) 4457129 Monthly Rollup
4457143 Security Only
Windows Server 2016 4457131 Security Update
Windows Server 2016 (Server Core installation) 4457131 Security Update
Windows Server, version 1709 (Server Core Installation) 4457142 Security Update
Windows Server, version 1803 (Server Core Installation) 4457128 Security Update