{"id":8369,"date":"2019-01-23T00:06:00","date_gmt":"2019-01-22T23:06:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=8369"},"modified":"2019-01-22T19:07:01","modified_gmt":"2019-01-22T18:07:01","slug":"micro-patch-for-windows-0-day-file-write-vulnerability","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2019\/01\/23\/micro-patch-for-windows-0-day-file-write-vulnerability\/","title":{"rendered":"Micro Patch for Windows 0-Day file write vulnerability"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/win102.jpg\" width=\"58\" align=\"left\" height=\"58\">In Windows there is a Zero-Day-Exploit, which allows you to overwrite files without permission. 0patch provides a temporary micro-patch for this bug after Microsoft did not patch it in January 2019. <\/p>\n<p><!--more--><\/p>\n<p>At the end of the year a new 0-Day bug in Windows has became known by a hacker using the alias SandboxEscaper. The vulnerability allows attackers to overwrite files (see my blog post <a href=\"https:\/\/borncity.com\/win\/2019\/01\/03\/windows-10-0-day-bug-enabled-file-overwrite\/\">Windows 10: 0-day bug enabled file overwrite<\/a>). <\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"de\">\n<p lang=\"en\" dir=\"ltr\">We have just issued a micropatch for SandboxEscaper's <a href=\"https:\/\/twitter.com\/hashtag\/angrypolarbearbug?src=hash&amp;ref_src=twsrc%5Etfw\">#angrypolarbearbug<\/a> 0day. The vulnerability allows a low-privileged user to have any file overwritten with the content of a Windows Error Reporting XML file. This could potentially lead to arbitrary code execution as SYSTEM. <a href=\"https:\/\/t.co\/KWzJ1nUNIo\">pic.twitter.com\/KWzJ1nUNIo<\/a><\/p>\n<p>\u2014 0patch (@0patch) <a href=\"https:\/\/twitter.com\/0patch\/status\/1085927178066366470?ref_src=twsrc%5Etfw\">17. Januar 2019<\/a><\/p><\/blockquote>\n<p><span id=\"preserve61a143da50c94693aef3fb365f47110f\" class=\"wlWriterPreserve\"><SCRIPT charset=\"utf-8\" src=\"https:\/\/platform.twitter.com\/widgets.js\" async><\/SCRIPT><\/span>  <\/p>\n<p>Now the provider 0patch has announced the availability of a micro-patch for Windows on Twitter. These micro patches can be downloaded from <a href=\"https:\/\/0patch.com\/\" target=\"_blank\">this website<\/a> by registered users. (<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/windows-zero-day-bug-that-overwrites-files-gets-interim-fix\/\" target=\"_blank\">via<\/a>)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In Windows there is a Zero-Day-Exploit, which allows you to overwrite files without permission. 0patch provides a temporary micro-patch for this bug after Microsoft did not patch it in January 2019.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,2],"tags":[69,76],"class_list":["post-8369","post","type-post","status-publish","format-standard","hentry","category-security","category-windows","tag-security","tag-windows-10"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/8369","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=8369"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/8369\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=8369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=8369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=8369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}