All Windows versions impacted by new Local Privilege Escalation (LPE) zero-day vulnerability

Discussion in 'other security issues & news' started by guest, Oct 28, 2021.

  1. guest

    guest Guest

    All Windows versions impacted by new LPE zero-day vulnerability
    October 28, 2021
    https://www.bleepingcomputer.com/ne...s-impacted-by-new-lpe-zero-day-vulnerability/
     
  2. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    Are we gonna post every single CVE now lol. Also i can't imagine they would post it before it's patched. So while u're reading it it's already patched and nothing to worry about, likely.
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    It's indeed true that most of the holes in Windows are not an immediate threat to especially home users. And who knows how many more zero days are present in Windows and others OS like macOS, so mitigation tools stay the most important.
     
  4. guest

    guest Guest

    Zero-day bug in all Windows versions gets free unofficial patch
    November 12, 2021
    https://www.bleepingcomputer.com/ne...-windows-versions-gets-free-unofficial-patch/
     
  5. guest

    guest Guest

    0-Day LPE Vulnerability in Windows Installer (Nov. 2021)
    November 23, 2021
    https://borncity.com/win/2021/11/23/0-day-lpe-schwachstelle-im-windows-installer-nov-2021/
     
  6. guest

    guest Guest

    Malware now trying to exploit new Windows Installer zero-day
    November 23, 2021
    https://www.bleepingcomputer.com/ne...ng-to-exploit-new-windows-installer-zero-day/
    Cisco Talos: Attackers exploiting zero-day vulnerability in Windows Installer — Here’s what you need to know and Talos’ coverage
     
  7. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,948
    Location:
    Outer space
    Actually they did, that happens quite often. It may be for self interest, but also for public interest. Sometimes companies don't respond or are very slow to work on a fix, with making a vulnerability public a researcher may want to force the company to fix it faster.
    I'm not sure if it is patched now, but it wasn't at the time of writing, that's why it is called a 0-day.
     
  8. guest

    guest Guest

    0Patch has a patch for Windows "InstallerFileTakeOver" 0-day vulnerability, Microsoft has none
    December 3, 2021
     
    Last edited by a moderator: Dec 6, 2021
  9. guest

    guest Guest

    After multiple Patch Tuesday fails, unofficial fix for an old Windows vulnerability released
    March 21, 2022
    0Patch: A Bug That Doesn't Want To Die (CVE-2021-34484)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.