New Windows Server 2012 zero-day gets free, unofficial patches

Teilen:

Free unofficial security patches have been released through the 0patch platform to address a zero-day vulnerability introduced over two years ago in the Windows Mark of the Web (MotW) security mechanism.

Windows automatically adds Mark of the Web (MotW) flags to all documents and executables downloaded from untrusted sources. These MotW labels inform the Windows operating system, Microsoft Office, web browsers, and other applications that the file should be treated cautiously.

As a result, users are warned that opening such files could lead to potentially dangerous behavior, such as installing malware on their devices.

According to Mitja Kolsek, co-founder of the 0patch micropatching service, this flaw can let attackers prevent Windows from applying (MotW) labels on some file types downloaded from the Internet.

“Our researchers discovered a previously unknown vulnerability on Windows Server 2012 and Server 2012 R2 that allows an attacker to bypass a security check otherwise enforced by Mark of the Web on certain types of files,” said Mitja Kolsek, co-founder of the 0patch micropatching service.

“Our analysis revealed this vulnerability was introduced to Windows Server 2012 over two years ago, and remained undetected – or at least unfixed – until today. It is even present on fully updated servers with Extended Security Updates.”

ACROS Security, the company behind 0Patch, will withhold information on this vulnerability until Microsoft releases official security patches that block potential attacks targeting vulnerable servers.

These unofficial patches are available for free for both legacy Windows versions and fully updated ones:

  • Windows Server 2012 updated to October 2023
  • Windows Server 2012 R2 updated to October 2023
  • Windows Server 2012 fully updated with Extended Security Updates
  • Windows Server 2012 R2 fully updated with Extended Security Updates

To install these micropatches on your Windows Server 2012 systems, register a 0patch account and install its agent. If there are no custom patching policies to block them, they will be deployed automatically after launching the agent (without requiring a system restart).

“Vulnerabilities like these get discovered on a regular basis, and attackers know about them all,” Kolsek added today.

“If you’re using Windows that aren’t receiving official security updates anymore, 0patch will make sure these vulnerabilities won’t be exploited on your computers – and you won’t even have to know or care about these things.”

A Microsoft spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:57 am, Feb. 1, 2025
Wetter-Symbol 5°C
L: 4° | H: 5°
overcast clouds
Luftfeuchtigkeit: 88 %
Druck: 1030 mb
Wind: 6 mph ESE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:38 am
Sonnenuntergang: 4:49 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
4° | 5°°C 0 mm 0% 6 mph 88 % 1030 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
2° | 7°°C 0 mm 0% 6 mph 84 % 1025 mb 0 mm/h
Mo. Feb. 03 9:00 pm
Wetter-Symbol
2° | 9°°C 0 mm 0% 5 mph 85 % 1026 mb 0 mm/h
Di. Feb. 04 9:00 pm
Wetter-Symbol
4° | 9°°C 1 mm 100% 12 mph 93 % 1026 mb 0 mm/h
Mi. Feb. 05 9:00 pm
Wetter-Symbol
4° | 8°°C 0.8 mm 80% 9 mph 91 % 1046 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 88 % 1030 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 6°°C 0 mm 0% 6 mph 83 % 1030 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 6 mph 76 % 1029 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 6 mph 79 % 1027 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 85 % 1026 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 5 mph 84 % 1024 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 83 % 1023 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 82 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€98,454.01
-1.96%
Ethereum(ETH)
€3,150.20
0.84%
XRP(XRP)
€2.92
-1.30%
Fesseln(USDT)
€0.97
-0.02%
Solana(SOL)
€221.45
-2.40%
USDC(USDC)
€0.97
0.00%
Dogecoin(DOGE)
€0.313073
-0.68%
Shiba Inu(SHIB)
€0.000018
1.30%
Pepe(PEPE)
€0.000013
4.15%
Nach oben scrollen