Blog | G5 Cyber Security

How We Micropatched a Publicly Dropped 0day in Task Scheduler (CVE-2018-8440)

Security researcher SandboxEscaper published details and proof-of-concept (POC) for a “0day” local privilege escalation vulnerability in Windows Task Scheduler service. This vulnerability allows a local unprivileged user to change permissions of any file on the system – and thus subsequently replace or modify that file. Official fix for this vulnerability is now available and users are advised to apply Windows Updates, which will automatically result in our micropatch not getting applied any more. Microsoft’s official fix is available.”]

Source: https://blog.0patch.com/2018/08/how-we-micropatched-publicly-dropped.html

Exit mobile version