{"id":2937,"date":"2017-05-27T13:16:43","date_gmt":"2017-05-27T11:16:43","guid":{"rendered":"http:\/\/borncity.com\/win\/?p=2937"},"modified":"2022-11-04T11:54:02","modified_gmt":"2022-11-04T10:54:02","slug":"windows-xpserver-2003-fix-for-nsa-esteemaudit-exploit","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2017\/05\/27\/windows-xpserver-2003-fix-for-nsa-esteemaudit-exploit\/","title":{"rendered":"Windows XP\/Server 2003: Fix for NSA ESTEEMAUDIT Exploit"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[<a href=\"http:\/\/www.borncity.com\/blog\/2017\/05\/27\/patch-fr-nsa-esteemaudit-exploit-windows-xpserver-2003\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Microsoft didn't release a patch for Windows XP, Windows Server 2003 to close the NSA ESTEEMAUDIT Exploit. Now security firm enSilo released a hotfix to close the vulnerability used by ESTEEMAUDIT exploit. <\/p>\n<p><!--more--><\/p>\n<p>After Shadow Broker released a couple of NSA hacking tools and exploits, Microsoft explained, that most of the vulnerabilities has been patched. Only some vulnerabilities addressed by exploits like <em>EsteemAudit <\/em>are unpatched, because Windows XP and Windows Server 2003 are reached end of life and are out of support. <\/p>\n<p>But after WannaCry-Attack we have learned, that unpatched vulnerabilities may cause infections of thousands of systems. And there are still many systems running Windows XP and\/or Windows Server 2003 out there. An analysis made from <a href=\"https:\/\/blog.fortinet.com\/2017\/05\/11\/deep-analysis-of-esteemaudit\">fortinet<\/a> showed, tha open RDP ports within a network allows to attack systems. <\/p>\n<p> Security firm enSilo decided to develop a hotfix for this <em>EsteemAudit <\/em>exploit. Last week they <a href=\"https:\/\/blog.ensilo.com\/ensilo-releases-free-patch-for-esteemaudit-exploit\" target=\"_blank\" rel=\"noopener noreferrer\">announced the patch<\/a>, that is public available for Windows XP SP3 x86\/x64 and Windows Server 2003 SP2. The patch will be loaded into winlogon.exe (only if it is an RDP session) to perform in memory patching (hotpatching) of ESTEEMAUDIT. Any attempt to use ESTEEMAUDIT to infect the patched machine will inevitably fail. <a href=\"https:\/\/web.archive.org\/web\/20191028190404\/https:\/\/pages.ensilo.com\/download-the-patch-for-esteemaudit-exploit\" target=\"_blank\" rel=\"noopener noreferrer\">Full details are available here<\/a>. (<a href=\"https:\/\/web.archive.org\/web\/20221019114053\/https:\/\/www.bleepingcomputer.com\/news\/security\/security-firm-releases-windows-xp-patch-for-nsa-exploit-esteemaudit\/\" target=\"_blank\" rel=\"noopener noreferrer\">via<\/a>)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft didn't release a patch for Windows XP, Windows Server 2003 to close the NSA ESTEEMAUDIT Exploit. Now security firm enSilo released a hotfix to close the vulnerability used by ESTEEMAUDIT exploit.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,2],"tags":[766,69,863,847],"class_list":["post-2937","post","type-post","status-publish","format-standard","hentry","category-security","category-windows","tag-patch","tag-security","tag-server-2003","tag-windows-xp"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/2937","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=2937"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/2937\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=2937"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=2937"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=2937"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}