If you’re still using Windows 7, download this patch now Windows 7


A free and temporary fix for a newly discovered zero-day in Windows 7 and Server 2008 R2 has been released by 0patch to prevent a local privilege escalation vulnerability from being actively exploited in the wild.
The bug affects all devices running Windows 7 and Server 2008 R2 regardless of whether or not these devices have been enrolled in Microsoft’s Extended Security Updates (ESU) program which costs between $25 and $200 per workstation.
The free micropatch released by 0patch will prevent the local privilege escalation vulnerability from being exploited by cybercriminals for systems without ESU and it will serve as a temporary fix for systems that are enrolled in the program until Microsoft releases a more permanent solution to the problem.
0patch provided more details on its new micropatch in a blog post, saying:
“According to our guidelines, this micropatch is free for everyone until Microsoft issues an official fix for it (presumably only as part of Extended Security Updates). By the time you’re reading this the micropatch has already been distributed to all online 0patch Agents and also automatically applied except where Enterprise policies prevented that.”
If you’re not yet an 0patch user and wish to install the micropatch on your systems, you can create an account in 0patch Central, install 0patch Agent and register it to your account.
Misconfigured registry keys
The local privilege escalation vulnerability is the result of two service registry keys being misconfigured and the bug could enable a local attacker to elevate their privileges on any system running Windows 7 and Server 2008 R2.
The zero-day was discovered by security researcher Clément Labro who recently published his analysis as well as a proof-of-concept that enabled 0patch to create its new micropatch for Windows users.
Insecure permissions on the HKLM\SYSTEM\CurrentControlSet\Services\Dnscache and HKLM\SYSTEM\CurrentControlSet\Services\RpcEptMapper registry keys makes it possible for an attacker to load malicious DLLs by tricking the RPC Endpoint Mapper.
Labro explained that he was surprised that the vulnerability he discovered wasn’t found sooner in his report detailing the zero-day, saying:
“I don’t know how this vulnerability has gone unnoticed for so long. One explanation is that other tools probably looked for full write access in the registry, whereas AppendData/AddSubdirectory was actually enough in this case. Regarding the “misconfiguration” itself, I would assume that the registry key was set this way for a specific purpose, although I can’t think of a concrete scenario in which users would have any kind of permissions to modify a service’s configuration.”
If you’re running Windows 7 or Server 2008 R2 on your systems you should install 0patch’s micropatch now regardless of whether you’re enrolled in Microsoft’s ESU program.
A free and temporary fix for a newly discovered zero-day in Windows 7 and Server 2008 R2 has been released by 0patch to prevent a local privilege escalation vulnerability from being actively exploited in the wild. The bug affects all devices running Windows 7 and Server 2008 R2 regardless of…
Recent Posts
- No, it’s not an April fool, Intel debuts open source AI offering that gauges a text’s politeness level
- It’s clearly time: all the news about the transparent tech renaissance
- Windows 11 24H2 hasn’t raised the bar for the operating system’s CPU requirements, Microsoft clarifies
- Acer is the first to raise laptop prices because of Trump
- OpenSSH vulnerabilities could pose huge threat to businesses everywhere
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010